← Back

CVE-2026-35433

nvd nist
Published: May 12, 2026Modified: Jul 15, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Exploitability: 1.8 / Impact: 5.5
Source: secure@microsoft.com (Secondary)

Description

Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

Affected (7)

2 products
.net
.net Framework
Configuration A
2 platform
Running on/withPlatform Versions
Microsoft
Windows 10 1607
All versions
Microsoft
Windows Server 2016
All versions
Configuration B
2 platform
Running on/withPlatform Versions
Microsoft
Windows Server 2012
All versions
Microsoft
Windows Server 2012
Version r2
Configuration C
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Microsoft
From 10.0.0 to 10.0.8
From 8.0.0 to 8.0.27
From 9.0.0 to 9.0.16
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration D
1 vulnerable · 9 platform
Vulnerable SoftwareAffected Versions
Version 4.8.1
Running on/withPlatform Versions
Microsoft
Windows 11 23h2
All versions
Microsoft
Windows 11 23h2
All versions
Microsoft
Windows 11 24h2
All versions
Microsoft
Windows 11 24h2
All versions
Microsoft
Windows 11 25h2
All versions
Microsoft
Windows 11 25h2
All versions
Microsoft
Windows 11 26h1
All versions
Microsoft
Windows 11 26h1
All versions
Microsoft
Windows Server 2025
All versions
Configuration E
1 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Version 4.8
Running on/withPlatform Versions
Microsoft
Windows 10 21h2
All versions
Microsoft
Windows 10 21h2
All versions
Microsoft
Windows 10 22h2
All versions
Microsoft
Windows 10 22h2
All versions
Microsoft
Windows Server 2022
All versions
Configuration F
2 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Microsoft
Version 3.5
Version 4.7.2
Running on/withPlatform Versions
Microsoft
Windows 10 1809
All versions
Microsoft
Windows 10 1809
All versions

References (4)

Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Timeline

No history available yet.