CVE-2025-55247: Microsoft .net

High severity, CVSS 7.3. EPSS: 0.6% chance of exploitation in the next 30 days.

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.

Affected products

  • Microsoft .net: from 8.0.0, before 8.0.21 (fixed in 8.0.21); from 9.0.0, before 9.0.10 (fixed in 9.0.10)

Published 2025-10-14. Last modified 2026-06-17.