CVE-2026-35433General(microsoft / .net)

LOWCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft .net systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-190

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • .net
  • .net_framework
  • windows
  • windows_10_1607

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-05-12); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
.net.net_frameworkwindowswindows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2

6 versions affected across 15 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-12: 3Mentions · 2026-05-15: 1Mentions · 2026-05-18: 1PoC Mentioned / Linked · 2026-05-12: 1Patch / Workaround · 2026-05-12: 2Technical Details · 2026-05-12: 2Technical Details · 2026-05-15: 1Technical Details · 2026-05-18: 105-1205-1505-18
Signal classification3 categories
General
240.0%
Patch
240.0%
Disclosure
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-123
General1Patch2
2026-05-151
General1
2026-05-181
Disclosure1
Full discourse5 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 NET, Improper Input Validation / Heap-based Buffer Overflow, #CVE-2026-35433 (High) https://dailycve.com/net-improper-input-validation-heap-based-buffer-overflow-cve-2026-35433-high/

    Post summary

    The post announces a new high‑severity heap‑based buffer overflow vulnerability in NET (CVE‑2026‑35433) as documented on DailyCVE.

    0000051
    206 followersView on X
  • Israel@f1tym1
    General

    CVE-2026-35433 | Microsoft .NET prior 10.0.8 input validation (Nessus ID 314680) https://ift.tt/Bf7xmls A vulnerability was found in Microsoft .NET. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. Performing a manipulation res…

    Post summary

    The post announces CVE‑2026‑35433 as a Microsoft .NET input‑validation issue before version 10.0.8, but provides no PoC, exploit, active‑use evidence, or patch details.

    0000032
    974 followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-35433: .NET elevation of privilege… with “trust us” details. That’s fun because .NET is basically Windows’ universal plumbing. Patch now, sleep later. #Windows #Security https://windowsforum.com/threads/cve-2026-35433-net-elevation-of-privilege-patch-with-confidence-in-may-2026.417807/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsAdministration #PatchTuesday #Cve2026 #NetSecurity https://t.co/4lSZaNsjhX

    Post summary

    The post announces that a patch has been released for CVE‑2026‑35433, a .NET elevation‑of‑privilege vulnerability, urging users to apply it.

    0000040
    1.1K followersView on X
  • America's Pick@nims213
    Patch

    Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-days https://ift.tt/CM9d4IR Tag CVE ID CVE Title Severity .NET CVE-2026-35433 .NET Elevation of Privilege Vulnerability Important .NET CVE-2026-32177 .NET Elevation of Privilege Vulnerability Important .NE…

    Post summary

    The tweet announces Microsoft Patch Tuesday for May 2026, noting that 120 flaws, including two .NET privilege‑escalation CVEs, were fixed with no zero‑days disclosed.

    0000034
    1.7K followersView on X
  • VulnersHub@VulnersHub
    General

    CVE-2026-35433 .NET Elevation of Privilege Vulnerability http://dlvr.it/TSVrYJ

    Post summary

    The post announces the existence of CVE‑2026‑35433, a .NET elevation-of-privilege issue, and provides a link that presumably contains further details.

    0000021
    6 followersView on X
CPE platform detail26 entries

26 of 26 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft.net---
Appmicrosoft.net_framework3.5--
Appmicrosoft.net_framework4.7.2--
Appmicrosoft.net_framework4.8--
Appmicrosoft.net_framework4.8.1--
OSmicrosoftwindows---
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1809--arm64
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2025--x64

Explore more