CVE-2026-62909: .NET Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Unlikely
- Patch Tuesday
- 2026-Aug
- Released
- 2026-08-11
Description
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
FAQ
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires that the target system be set up in a specific manner and the attacker to have knowledge of that setup.
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain ROOT privileges.
Affected Products (11)
Developer Tools
- .NET 10.0 installed on Linux
- .NET 8.0 installed on Linux
- .NET 9.0 installed on Linux
- Microsoft Visual Studio 2026 version 18.8
- .NET 10.0 installed on Mac OS
- .NET 10.0 installed on Windows
- .NET 8.0 installed on Windows
- .NET 8.0 installed on Mac OS
- .NET 9.0 installed on Mac OS
- Microsoft Visual Studio 2022 version 17.14
- .NET 9.0 installed on Windows
Security Updates (3)
Acknowledgments
<a href="https://x.com/kookiz/">Kevin Gosse</a>
Revision History
- 2026-08-11: Information published.