CVE-2025-55247

Published: October 16, 2025Last modified: October 16, 2025

Description

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.

Severity score breakdown

ParameterValue
Base score7.3
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux25 LTSdotnet8-runtimeVulnerable (8.0.17-r0)
dotnet8-sdkVulnerable (8.0.117-r0)
Streamdotnet8-runtimeVulnerable (8.0.11-r1)
dotnet8-sdkVulnerable (8.0.117-r0)

References

ON THIS PAGE