External File Path Control in Microsoft .NET Enables Network Privilege Escalation
AI analysis
Microsoft .NET contains a privilege elevation flaw (CWE-73) in which a file name or path processed by the .NET runtime is externally controlled, allowing an unauthorized attacker to elevate privileges over a network. Exploitation requires network access, user interaction, and a high-complexity attack path (CVSS AV:N/AC:H/PR:N/UI:R), meaning the attacker must induce a user into an action that causes .NET to process an attacker-influenced file path, though no privileges are needed. A successful attack carries high impact to confidentiality, integrity, and availability, and the associated CWEs (CWE-200, CWE-522) suggest possible information exposure and insufficiently protected credentials as related effects. Any organization running affected .NET runtimes, SDKs, or .NET Framework installations is potentially exposed; exact version ranges are not specified in the available data, and fixes shipped as part of Microsoft's September 2026 Patch Tuesday (September 8, 2026). There are no known reports of exploitation, no public proof-of-concept, the flaw is absent from CISA's KEV catalog, and EPSS assigns only a 0.5% probability of exploitation within 30 days (42nd percentile).
What to do: Inventory all .NET runtimes, SDKs, and .NET Framework installations and apply the .NET updates released in Microsoft's September 2026 Patch Tuesday, checking Microsoft's advisory for the specific affected version ranges since they are not listed in the available data. Prioritize user-facing and developer systems where users may be induced to handle untrusted content, and watch Microsoft's guidance for any published workarounds or version-specific remediation details.
Estimated exposure
masshundreds of millions of endpoints and servers potentially affected (ubiquitous .NET install base; vulnerable subset unconfirmed) — .NET Framework is a default component of Windows and .NET runtimes and SDKs are widely deployed across enterprise servers, cloud workloads, and developer machines, so the potential install base is enormous; since affected version ranges…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.