CVE-2026-69439: .NET and Visual Studio Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 8.8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Unlikely
Patch Tuesday
2026-Sep
Released
2026-09-08

Description

Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.

FAQ

How could an attacker exploit this vulnerability? An attacker could exploit this vulnerability by convincing a user or service to process a specially crafted Portable PDB file. Successful exploitation could allow the attacker to execute code with the privileges of the affected process. What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain the privileges of the user account or service account running the affected process.

Affected Products (6)

Developer Tools

  • .NET 10.0 installed on Windows
  • .NET 8.0 installed on Windows
  • .NET 9.0 installed on Windows
  • Microsoft Visual Studio 2022 version 17.14
  • Microsoft Visual Studio 2026 version 18.9
  • .NET 11.0 installed on Windows

Security Updates (6)

Acknowledgments

41ae55e9310ff27fa6f26af4727e5590

Revision History

  • 2026-09-08: Information published.