CVE-2026-62909HighCVSS 7.8
.NET Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
🎯 Affected products11
- .NET 10.0 installed on Linux
- .NET 10.0 installed on Mac OS
- .NET 10.0 installed on Windows
- .NET 8.0 installed on Linux
- .NET 8.0 installed on Mac OS
- .NET 8.0 installed on Windows
- .NET 9.0 installed on Linux
- .NET 9.0 installed on Mac OS
- .NET 9.0 installed on Windows
- Microsoft Visual Studio 2022 version 17.14
- Microsoft Visual Studio 2026 version 18.8
✅ Remediation
KB5122106 (Security Update) — fixed build 10.0.11 KB5122104 (Security Update) — fixed build 8.0.30 KB5122105 (Security Update) — fixed build 9.0.19 Security Update — fixed build 18.8.3 Security Update — fixed build 17.14.38
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62909
- patchhttps://dotnet.microsoft.com/download/dotnet/10.0
- referencehttps://support.microsoft.com/help/5122106
- patchhttps://dotnet.microsoft.com/download/dotnet/8.0
- referencehttps://support.microsoft.com/help/5122104
- patchhttps://dotnet.microsoft.com/download/dotnet/9.0
- referencehttps://support.microsoft.com/help/5122105