CVE Tools

CVE-2026-62909

.NET Elevation of Privilege Vulnerability

Published: Aug 11, 2026Updated: Aug 14, 2026 Sources: CVE List NVDCWE-252

Description

Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.

In plain language

AI Act now

CVE-2026-62909 is a .NET security flaw that lets a local attacker with low-level access break out of their permissions and take full control of your machine; if you use affected versions of .NET or Visual Studio, you should update now.

Executive summary

CVE-2026-62909 is a local privilege escalation in .NET (CWE-252) where low-privileged access can trigger an unhandled error/exception to gain full system control; it does not require user interaction and is reachable in default configurations.

If affected, business impact
Full workstation takeoverAccess to sensitive project dataAbility to install malwareService disruption on dev machines

What to do now

  1. Check whether you run or develop on these installed versions: .NET 8.0, .NET 9.0, .NET 10.0, and Visual Studio 2022 (17.14) or Visual Studio 2026 (18.8).
  2. If your versions are older than the fixed releases below, schedule updates as soon as possible.
  3. Update Visual Studio 2022 to 17.14.38.
  4. Update Visual Studio 2026 to 18.8.3.
  5. Update .NET 8.0 to 8.0.30.
  6. Update .NET 9.0 to 9.0.19.
  7. Update .NET 10.0 to 10.0.11.
  8. After updating, verify the updated versions are in place and that your build/dev workflows still work normally.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:LAC:HPR:LUI:NS:CC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:HAttack Complexity
High
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

Official Patch Available

References

2

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-62909 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows