CVE-2026-45490: .NET SDK Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Jun
- Released
- 2026-06-09
- EPSS Score
- 0.38% (percentile: 30.9%)
Description
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
FAQ
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Affected Products (3)
Developer Tools
- .NET 10.0 installed on Windows
- .NET 8.0 installed on Windows
- .NET 9.0 installed on Windows
Security Updates (3)
Acknowledgments
Ky0toFu, 41ae55e9310ff27fa6f26af4727e5590, chupaohong
Revision History
- 2026-06-09: Information published.