CyberICT

CVE-2025-55247

Microsoft · Published October 14, 2025

CVSS v3.1

HIGH
Patch availableGet patch

Description

.NET Elevation of Privilege Vulnerability. Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.

Affected Products

  • .NET 8.0 installed on Linux
  • .NET 9.0 installed on Linux

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C