.NET Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
🎯 Affected products50
- .NET 10.0 installed on Windows
- .NET 8.0 installed on Windows
- .NET 9.0 installed on Windows
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2019
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems
- +20 more not shown
✅ Remediation
KB5120716 (Security Update) — fixed build 2.0.50727.8984 & 3.0.30729.8980 KB5126044 (Security Update) — fixed build 4.7.4145.0 KB5126049 (Security Update) — fixed build 4.8.4806.0 KB5126051 (Security Update) — fixed build 4.8.4806.0 KB5126047 (Security Update) — fixed build 4.8.4806.0 KB5126043 (Security Update) — fixed build 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4145.0 KB5126048 (Security Update) — fixed build 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4806.0 KB5126422 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9347.0 KB5126421 (Security Update) — fixed build 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4806.0 KB5126046 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4806.0 KB5126421 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9346.0 KB5126052 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9347.0 KB5120747 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 KB5126053 (Security Update) — fixed build 4.8.9347.0 KB5120695 (Security Update) — fixed build 3.0.50727.8984 KB5126045 (Security Update) — fixed build 4.7.4145.0 KB5123099 (Security Update) — fixed build 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4145.0 KB5126050 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4806.0 KB5126424 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9347.0 Security Update — fixed build 18.8.3 KB5122106 (Security Update) — fixed build 10.0.11 KB5122104 (Security Update) — fixed build 8.0.30 KB5122105 (Security Update) — fixed build 9.0.19 Security Update — fixed build 17.14.38
🔗 References (40)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62886
- referencehttps://support.microsoft.com/help/5120716
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126044
- referencehttps://support.microsoft.com/help/5126044
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126049
- referencehttps://support.microsoft.com/help/5126049
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126051
- referencehttps://support.microsoft.com/help/5126051
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126047
- referencehttps://support.microsoft.com/help/5126047
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126043
- referencehttps://support.microsoft.com/help/5126043
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126048
- referencehttps://support.microsoft.com/help/5126048
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126422
- referencehttps://support.microsoft.com/help/5126422
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126421
- referencehttps://support.microsoft.com/help/5126421
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126046
- referencehttps://support.microsoft.com/help/5126046
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126052
- referencehttps://support.microsoft.com/help/5126052
- referencehttps://support.microsoft.com/help/5120747
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126053
- referencehttps://support.microsoft.com/help/5126053
- referencehttps://support.microsoft.com/help/5120695
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126045
- referencehttps://support.microsoft.com/help/5126045
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5123099
- referencehttps://support.microsoft.com/help/5123099
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126050
- referencehttps://support.microsoft.com/help/5126050
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5126424
- referencehttps://support.microsoft.com/help/5126424
- patchhttps://dotnet.microsoft.com/download/dotnet/10.0
- referencehttps://support.microsoft.com/help/5122106
- patchhttps://dotnet.microsoft.com/download/dotnet/8.0
- referencehttps://support.microsoft.com/help/5122104
- patchhttps://dotnet.microsoft.com/download/dotnet/9.0
- referencehttps://support.microsoft.com/help/5122105