CVE-2026-62909
.NET Elevation of Privilege Vulnerability
Description
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-62909 is a .NET security flaw that lets a local attacker with low-level access break out of their permissions and take full control of your machine; if you use affected versions of .NET or Visual Studio, you should update now.
Executive summary
CVE-2026-62909 is a local privilege escalation in .NET (CWE-252) where low-privileged access can trigger an unhandled error/exception to gain full system control; it does not require user interaction and is reachable in default configurations.
If affected, business impact
Full workstation takeoverAccess to sensitive project dataAbility to install malwareService disruption on dev machines
What to do now
- Check whether you run or develop on these installed versions: .NET 8.0, .NET 9.0, .NET 10.0, and Visual Studio 2022 (17.14) or Visual Studio 2026 (18.8).
- If your versions are older than the fixed releases below, schedule updates as soon as possible.
- Update Visual Studio 2022 to 17.14.38.
- Update Visual Studio 2026 to 18.8.3.
- Update .NET 8.0 to 8.0.30.
- Update .NET 9.0 to 9.0.19.
- Update .NET 10.0 to 10.0.11.
- After updating, verify the updated versions are in place and that your build/dev workflows still work normally.
Patch / advisory Usually a quick update
CVSS Vector Breakdown
Exploitability
AV:LAttack VectorLocal
AC:HAttack ComplexityHigh
PR:LPrivileges RequiredLow
UI:NUser InteractionNone
Scope
S:CScopeChanged
Impact
C:HConfidentialityHigh
I:HIntegrityHigh
A:HAvailabilityHigh
Weaknesses
Affected Products
Exploitability
Official Patch Available
References
News mentions
2Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62909 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows
