{"api_version":"1","generated_at":"2026-07-23T13:42:40+00:00","cve":"CVE-2026-35433","urls":{"html":"https://cve.report/CVE-2026-35433","api":"https://cve.report/api/cve/CVE-2026-35433.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-35433","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-35433"},"summary":{"title":".NET Elevation of Privilege Vulnerability","description":"Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.","state":"PUBLISHED","assigner":"microsoft","published_at":"2026-05-12 18:17:13","updated_at":"2026-07-15 02:20:42"},"problem_types":["CWE-20","CWE-190","NVD-CWE-noinfo","CWE-20 CWE-20: Improper Input Validation","CWE-190 CWE-190: Integer Overflow or Wraparound","CWE-20 Improper Input Validation"],"metrics":[{"version":"3.1","source":"ADP","type":"CVSS","score":"7.3","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","version":"3.1"}},{"version":"3.1","source":"secure@microsoft.com","type":"Secondary","score":"7.3","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"}},{"version":"3.1","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","score":"7.3","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.3","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C","data":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C","version":"3.1"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2476577","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2476577","refsource":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35433","name":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35433","refsource":"secure@microsoft.com","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-35433","name":"https://access.redhat.com/security/cve/CVE-2026-35433","refsource":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35433.json","name":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35433.json","refsource":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-35433","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35433","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Microsoft","product":".NET 10.0","version":"affected 10.0.0 10.0.8 custom","platforms":[]},{"source":"CNA","vendor":"Microsoft","product":".NET 8.0","version":"affected 8.0.0 8.0.27 custom","platforms":[]},{"source":"CNA","vendor":"Microsoft","product":".NET 9.0","version":"affected 9.0.0 9.0.16 custom","platforms":[]},{"source":"CNA","vendor":"Microsoft","product":"Microsoft .NET Framework 3.5","version":"affected 3.5.0 4.8.9334.0 and 4.8.4802.0 custom","platforms":["Windows Server 2012","Windows Server 2012 R2"]},{"source":"CNA","vendor":"Microsoft","product":"Microsoft .NET Framework 3.5 AND 4.7.2","version":"affected 4.7.0 4.8.9334.0 and 4.8.4802.0 custom","platforms":["Windows 10 Version 1809 for ARM64-based Systems","Windows 10 Version 1809 for x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Microsoft .NET Framework 3.5 AND 4.8","version":"affected 4.8.0 4.8.9334.0 and 4.8.4802.0 custom","platforms":["Windows 10 Version 1809 for ARM64-based Systems","Windows 10 Version 1809 for x64-based Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows Server 2022"]},{"source":"CNA","vendor":"Microsoft","product":"Microsoft .NET Framework 3.5 AND 4.8.1","version":"affected 4.8.1 4.8.9334.0 and 4.8.4802.0 custom","platforms":["Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems","Windows 11 version 26H1 for x64-based Systems","Windows Server 2022","Windows Server 2025"]},{"source":"CNA","vendor":"Microsoft","product":"Microsoft .NET Framework 4.8","version":"affected 4.8.0 4.8.9334.0 and 4.8.4802.0 custom","platforms":["Windows 10 Version 1607 for x64-based Systems","Windows Server 2012","Windows Server 2012 R2","Windows Server 2016"]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Hardened Images","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Hardened Images","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Hardened Images","version":"","platforms":[]}],"timeline":[{"source":"ADP","time":"2026-05-12T18:01:11.848Z","lang":"en","value":"Reported to Red Hat."},{"source":"ADP","time":"2026-05-12T16:58:34.612Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"35433","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":".net_framework","cpe6":"3.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"35433","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":".net_framework","cpe6":"4.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"35433","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_1607","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x64","cpe13":"*"},{"cve_year":"2026","cve_id":"35433","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2012","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"35433","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2012","cpe6":"r2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"35433","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2016","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"35433","cve":"CVE-2026-35433","epss":"0.005280000","percentile":"0.404970000","score_date":"2026-06-24","updated_at":"2026-06-25 00:05:31"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-35433","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-05-13T03:55:58.313299Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-05-19T16:49:09.046Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10"],"defaultStatus":"unaffected","packageName":"dotnet10.0","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10"],"defaultStatus":"unaffected","packageName":"dotnet8.0","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10"],"defaultStatus":"unaffected","packageName":"dotnet9.0","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:8"],"defaultStatus":"unaffected","packageName":"dotnet10.0","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:8"],"defaultStatus":"unaffected","packageName":"dotnet8.0","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:8"],"defaultStatus":"unaffected","packageName":"dotnet9.0","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:9"],"defaultStatus":"unaffected","packageName":"dotnet10.0","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:9"],"defaultStatus":"unaffected","packageName":"dotnet8.0","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:9"],"defaultStatus":"unaffected","packageName":"dotnet9.0","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:hummingbird:1"],"defaultStatus":"unaffected","packageName":"dotnet10.0","product":"Red Hat Hardened Images","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:hummingbird:1"],"defaultStatus":"unaffected","packageName":"dotnet8.0","product":"Red Hat Hardened Images","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:hummingbird:1"],"defaultStatus":"unaffected","packageName":"dotnet9.0","product":"Red Hat Hardened Images","vendor":"Red Hat"}],"datePublic":"2026-05-12T16:58:34.612Z","descriptions":[{"lang":"en","value":"A flaw was found in dotnet. Improper input validation and an integer overflow in .NET allow an unauthenticated attacker to elevate privileges locally."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Important"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-20","description":"Improper Input Validation","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-15T01:02:48.658Z","orgId":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","shortName":"redhat-SADP"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-35433"},{"name":"RHBZ#2476577","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2476577"},{"tags":["x_sadp-csaf-vex"],"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35433.json"}],"timeline":[{"lang":"en","time":"2026-05-12T18:01:11.848Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-05-12T16:58:34.612Z","value":"Made public."}],"title":"dotnet: .NET: improper input validation allows an attacker to elevate privileges locally","x_adpType":"supplier","x_generator":{"engine":"sadp-cli 1.0.0"}}],"cna":{"affected":[{"product":".NET 10.0","vendor":"Microsoft","versions":[{"lessThan":"10.0.8","status":"affected","version":"10.0.0","versionType":"custom"}]},{"product":".NET 8.0","vendor":"Microsoft","versions":[{"lessThan":"8.0.27","status":"affected","version":"8.0.0","versionType":"custom"}]},{"product":".NET 9.0","vendor":"Microsoft","versions":[{"lessThan":"9.0.16","status":"affected","version":"9.0.0","versionType":"custom"}]},{"platforms":["Windows Server 2012","Windows Server 2012 R2"],"product":"Microsoft .NET Framework 3.5","vendor":"Microsoft","versions":[{"lessThan":"4.8.9334.0 and 4.8.4802.0","status":"affected","version":"3.5.0","versionType":"custom"}]},{"platforms":["Windows 10 Version 1809 for ARM64-based Systems","Windows 10 Version 1809 for x64-based Systems"],"product":"Microsoft .NET Framework 3.5 AND 4.7.2","vendor":"Microsoft","versions":[{"lessThan":"4.8.9334.0 and 4.8.4802.0","status":"affected","version":"4.7.0","versionType":"custom"}]},{"platforms":["Windows 10 Version 1809 for ARM64-based Systems","Windows 10 Version 1809 for x64-based Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows Server 2022"],"product":"Microsoft .NET Framework 3.5 AND 4.8","vendor":"Microsoft","versions":[{"lessThan":"4.8.9334.0 and 4.8.4802.0","status":"affected","version":"4.8.0","versionType":"custom"}]},{"platforms":["Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems","Windows 11 version 26H1 for x64-based Systems","Windows Server 2022","Windows Server 2025"],"product":"Microsoft .NET Framework 3.5 AND 4.8.1","vendor":"Microsoft","versions":[{"lessThan":"4.8.9334.0 and 4.8.4802.0","status":"affected","version":"4.8.1","versionType":"custom"}]},{"platforms":["Windows 10 Version 1607 for x64-based Systems","Windows Server 2012","Windows Server 2012 R2","Windows Server 2016"],"product":"Microsoft .NET Framework 4.8","vendor":"Microsoft","versions":[{"lessThan":"4.8.9334.0 and 4.8.4802.0","status":"affected","version":"4.8.0","versionType":"custom"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.8","versionStartIncluding":"10.0.0","vulnerable":true},{"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionEndExcluding":"8.0.27","versionStartIncluding":"8.0.0","vulnerable":true},{"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionEndExcluding":"9.0.16","versionStartIncluding":"9.0.0","vulnerable":true},{"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionEndExcluding":"4.8.9334.0 and 4.8.4802.0","versionStartIncluding":"4.8.0","vulnerable":true},{"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionEndExcluding":"4.8.9334.0 and 4.8.4802.0","versionStartIncluding":"4.8.0","vulnerable":true},{"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionEndExcluding":"4.8.9334.0 and 4.8.4802.0","versionStartIncluding":"4.7.0","vulnerable":true},{"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionEndExcluding":"4.8.9334.0 and 4.8.4802.0","versionStartIncluding":"4.8.1","vulnerable":true},{"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionEndExcluding":"4.8.9334.0 and 4.8.4802.0","versionStartIncluding":"3.5.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"datePublic":"2026-05-12T14:00:00.000Z","descriptions":[{"lang":"en-US","value":"Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally."}],"metrics":[{"cvssV3_1":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en-US","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en-US","type":"CWE"},{"cweId":"CWE-190","description":"CWE-190: Integer Overflow or Wraparound","lang":"en-US","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-19T16:13:23.315Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":".NET Elevation of Privilege Vulnerability","tags":["vendor-advisory","patch"],"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35433"}],"title":".NET Elevation of Privilege Vulnerability"}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2026-35433","datePublished":"2026-05-12T16:58:34.612Z","dateReserved":"2026-04-02T19:21:11.804Z","dateUpdated":"2026-07-15T01:02:48.658Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-05-12 18:17:13","lastModifiedDate":"2026-07-15 02:20:42","problem_types":["CWE-20","CWE-190","NVD-CWE-noinfo","CWE-20 CWE-20: Improper Input Validation","CWE-190 CWE-190: Integer Overflow or Wraparound","CWE-20 Improper Input Validation"],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":5.5},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-13T03:55:58.313299Z","id":"CVE-2026-35433","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*","matchCriteriaId":"2D3F18AF-84ED-473B-A8DF-65EB23C475AF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*","matchCriteriaId":"5E491E46-1917-41FE-8F9A-BB0BDDEB42C3"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","matchCriteriaId":"A7DF96F8-BA6A-4780-9CA3-F719B3F81074"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","matchCriteriaId":"DB18C4CE-5917-401E-ACF7-2747084FD36E"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*","matchCriteriaId":"041FF8BA-0B12-4A1F-B4BF-9C4F33B7C1E7"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*","matchCriteriaId":"E039CE1F-B988-4741-AE2E-5B36E2AF9688"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","matchCriteriaId":"A7DF96F8-BA6A-4780-9CA3-F719B3F81074"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","matchCriteriaId":"DB18C4CE-5917-401E-ACF7-2747084FD36E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"8.0.27","matchCriteriaId":"22FEE1A6-0E92-4E1A-B3C0-AD8DF6EE7B7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"9.0.16","matchCriteriaId":"1F144BCB-8CEA-451A-9048-2A706EA67262"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"10.0.8","matchCriteriaId":"480D562B-C22F-4227-B1F2-1DFA7E239DC7"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*","matchCriteriaId":"E039CE1F-B988-4741-AE2E-5B36E2AF9688"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.8.1:*:*:*:*:*:*:*","matchCriteriaId":"934D4E46-12C1-41DC-A28C-A2C430E965E4"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_23h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"B0301BA0-81DB-4FC1-9BC3-EB48A56BC608"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_23h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"8E3C1327-F331-4448-A253-00EAC7428317"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"08EE1F3A-A8DE-4867-BB5B-8A8ED867F3CA"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"B1670829-6A8C-4688-B7A5-3DFB878A4861"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"024EE6EC-6D62-4EAC-B1EF-A5E4EAD439A1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"25D142AB-B61D-43F3-B7E6-DB9140EFEF75"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:-:*:*:*:*:*:arm64:*","matchCriteriaId":"CBFE0371-0C4D-406A-9EC7-456104271C3E"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:-:*:*:*:*:*:x64:*","matchCriteriaId":"F2B83840-FCE8-445A-AE55-ACEDA6534FA1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*","matchCriteriaId":"821614DD-37DD-44E2-A8A4-FE8D23A33C3C"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2025:-:*:*:*:*:*:x64:*","matchCriteriaId":"FE97605F-7942-435A-9F5B-D51FA19A41AD"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*","matchCriteriaId":"E039CE1F-B988-4741-AE2E-5B36E2AF9688"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*","matchCriteriaId":"2D3F18AF-84ED-473B-A8DF-65EB23C475AF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:*","matchCriteriaId":"73D24713-D897-408D-893B-77A61982597D"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*","matchCriteriaId":"306B7CE6-8239-4AED-9ED4-4C9F5B349F58"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"8FC46499-DB6E-48BF-9334-85EE27AFE7AF"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"83A79DD6-E74E-419F-93F1-323B68502633"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"A9D54EE6-30AF-411C-A285-A4DCB6C6EC06"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"C230D3BF-7FCE-405C-B62E-B9190C995C3C"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*","matchCriteriaId":"821614DD-37DD-44E2-A8A4-FE8D23A33C3C"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*","matchCriteriaId":"E039CE1F-B988-4741-AE2E-5B36E2AF9688"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*","matchCriteriaId":"3EF7A75E-EE27-4AA7-8D84-9D696728A4CE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:*","matchCriteriaId":"73D24713-D897-408D-893B-77A61982597D"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*","matchCriteriaId":"306B7CE6-8239-4AED-9ED4-4C9F5B349F58"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"35433","Ordinal":"1","Title":".NET Elevation of Privilege Vulnerability","CVE":"CVE-2026-35433","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"35433","Ordinal":"1","NoteData":"Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.","Type":"Description","Title":".NET Elevation of Privilege Vulnerability"}]}}}