Information Disclosure Vulnerability in Microsoft QUIC
CVE-2026-62898

7.5HIGH

What is CVE-2026-62898?

An issue within Microsoft QUIC has been identified that allows unauthorized attackers to disclose sensitive information over the network. This vulnerability arises from the 'use after free' condition, which can be exploited to gain access to data that should remain secure, posing significant risks to user privacy and corporate information integrity. Immediate attention and patching are recommended to mitigate potential exploitations.

Affected Version(s)

.NET 10.0 10.0.0 < 10.0.11

.NET 8.0 8.0.0 < 8.0.30

.NET 9.0 9.0.0 < 9.0.19

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.