CVE-2026-35433 Details
Description
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
A vulnerability in .NET has been identified, allowing unauthorized attackers to locally elevate privileges. This issue arises from improper input validation, which could enable attackers to gain SYSTEM privileges.
Users can download the security update for .NET 9.0, 8.0, or 10.0 installed on Windows. For .NET 9.0, the security update is available through the .NET website. Similar guidance applies to the other versions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-35433 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2476577 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35433.json | redhat-SADP | |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35433 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
| CWE-20 | Improper Input Validation | redhat-SADP |
| CWE-20 | Improper Input Validation | [email protected] |
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft .net framework | 4.8 3.5 4.8.1 4.7.2 |
CPE
Remediation
| |
| microsoft windows 10 1607 | All versions |
CPE
Remediation
| |
| microsoft windows server 2012 | r2 |
CPE
Remediation
| |
| microsoft windows server 2016 | All versions |
CPE
Remediation
| |
| microsoft .net | >= 8.0.0, < 8.0.27 >= 9.0.0, < 9.0.16 >= 10.0.0, < 10.0.8 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| microsoft windows 11 23h2 | All versions |
CPE
Remediation
| |
| microsoft windows 11 24h2 | All versions |
CPE
Remediation
| |
| microsoft windows 11 25h2 | All versions |
CPE
Remediation
| |
| microsoft windows 11 26h1 | All versions |
CPE
Remediation
| |
| microsoft windows server 2022 | All versions |
CPE
Remediation
| |
| microsoft windows server 2025 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1809 | All versions |
CPE
Remediation
| |
| microsoft windows 10 21h2 | All versions |
CPE
Remediation
| |
| microsoft windows 10 22h2 | All versions |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 18, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | CVE Modified | [email protected] |
| Jun 5, 2026 | CVE Modified | [email protected] |
| Jun 1, 2026 | CVE Modified | [email protected] |
| May 12, 2026 | New CVE Received | [email protected] |