CVE-2025-55247

HIGH7.3EPSS 0.02%

.NET Elevation of Privilege Vulnerability

Published: 10/15/2025Modified: 10/24/2025
Also known as:GHSA-w3q9-fxm7-j8fqBIT-dotnet-2025-55247BIT-dotnet-sdk-2025-55247

Description

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

References (4)