CVE-2026-62872
.NET Framework Elevation of Privilege Vulnerability
Description
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
In plain language
AI Act nowCVE-2026-62872 is a .NET Framework security bug where an attacker who already has low-level access can use the network to gain full administrative control; most small businesses should patch urgently because it’s reachable in default setups.
CVE-2026-62872 is an authorization flaw (CWE-863) in Microsoft .NET Framework where an authenticated attacker with low privileges can, over the network, bypass incorrect authorization checks to elevate to high-privilege control.
What to do now
- Check whether your servers/apps are using Microsoft .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, or 4.8.1.
- For each affected .NET Framework install, confirm the installed version is below the fixed builds listed by Microsoft for CVE-2026-62872.
- Upgrade/patch each affected .NET Framework to the corresponding fixed version from Microsoft’s update guide for CVE-2026-62872.
- If patching is delayed, reduce exposure by restricting network access to any systems/services that use .NET Framework and log/monitor for unusual privilege changes and authentication activity.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62872 and every CVE in our database. Create a free account — no credit card required.
Create Free Account