Privilege Elevation Vulnerability in .NET by Microsoft
CVE-2026-62909

7.8HIGH

What is CVE-2026-62909?

An issue in .NET could enable an authenticated attacker to gain elevated privileges on the local machine. This vulnerability arises from an unhandled exception, which may allow attackers to execute unauthorized actions within the system. It is crucial for users of the affected .NET versions to apply the necessary security updates and patches to mitigate potential exploitation risks.

Affected Version(s)

.NET 10.0 10.0.0 < 10.0.11

.NET 8.0 8.0.0 < 8.0.30

.NET 9.0 9.0.0 < 9.0.19

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.