CVE-2026-65810
.NET Framework Elevation of Privilege Vulnerability
Description
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-65810 is a .NET Framework flaw where a local attacker can trick the software into using file paths outside the intended area, which may let them gain higher privileges; small businesses should fix it if you run affected .NET Framework versions, especially on machines that could be reached by users or low-privilege accounts.
CVE-2026-65810 is a local privilege-escalation issue in .NET Framework caused by improper handling of relative file paths (path traversal), allowing an attacker to read/write files outside the intended directory and then elevate privileges; authentication is not required, but user interaction is required.
What to do now
- Check whether your Windows devices running .NET Framework are on one of these vulnerable versions: Microsoft .NET Framework 3.5; Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2; Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2; Microsoft .NET Framework 4.8; Microsoft .NET Framework 4.8.1.
- For each affected device, compare the installed .NET file versions against the fixed versions listed by Microsoft for CVE-2026-65810.
- Patch immediately to the fixed versions for your installed .NET Framework line (from the list below):
- .NET Framework 3.5: fixed in 2.0.50727.9183 and 3.0.30729.9169
- .NET Framework 3.5 and 4.6.2/4.7/4.7.1/4.7.2: fixed in 2.0.50727.8984, 3.0.30729.8980, and 4.7.4144.0
- .NET Framework 3.5 and 4.7.2: fixed in 2.0.50727.9070, 3.0.30729.9068, and 4.7.4144.0
- .NET Framework 3.5 and 4.8: fixed in 2.0.50727.9070, 3.0.30729.9068, and 4.8.4805.0
- .NET Framework 3.5 and 4.8.1: fixed in 2.0.50727.9183, 3.0.30729.9169, and 4.8.9343.0
- .NET Framework 4.6.2/4.7/4.7.1/4.7.2: fixed in 4.7.4144.0
- .NET Framework 4.8: fixed in 4.8.4805.0
- .NET Framework 4.8.1: fixed in 4.8.9344.0
- If you can’t patch right away, reduce exposure by limiting which local users can run interactive actions on the affected machines, and prioritize patching on systems where low-privilege users can access the machine.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-65810 and every CVE in our database. Create a free account — no credit card required.
Create Free Account