CVE-2026-62909: .NET Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Unlikely
Patch Tuesday
2026-Aug
Released
2026-08-11

Description

Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.

FAQ

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires that the target system be set up in a specific manner and the attacker to have knowledge of that setup. What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain ROOT privileges.

Affected Products (11)

Developer Tools

  • .NET 10.0 installed on Linux
  • .NET 8.0 installed on Linux
  • .NET 9.0 installed on Linux
  • Microsoft Visual Studio 2026 version 18.8
  • .NET 10.0 installed on Mac OS
  • .NET 10.0 installed on Windows
  • .NET 8.0 installed on Windows
  • .NET 8.0 installed on Mac OS
  • .NET 9.0 installed on Mac OS
  • Microsoft Visual Studio 2022 version 17.14
  • .NET 9.0 installed on Windows

Security Updates (3)

Acknowledgments

<a href="https://x.com/kookiz/">Kevin Gosse</a>

Revision History

  • 2026-08-11: Information published.