{"id":"CVE-2026-62909","title":".NET Elevation of Privilege Vulnerability","summary":"Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C","cvssSource":"cna","cwe":["CWE-252","CWE-248"],"vendor":"Microsoft","product":".NET 10.0","affected":[".net_10.0 >= 10.0.0 < 10.0.11",".net_8.0 >= 8.0.0 < 8.0.30",".net_9.0 >= 9.0.0 < 9.0.19","visual_studio_2022_version_17.14 >= 17.14.0 < 17.14.38","visual_studio_2026_version_18.8 >= 18.0 < 18.8.3"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-08-12T03:55:32.907064Z"},"published":"2026-08-11","updated":"2026-09-16","sourceUpdated":"2026-09-16T16:24:10.606Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-62909","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62909","label":".NET Elevation of Privilege Vulnerability"},{"url":"https://github.com/dotnet/runtime/security/advisories/GHSA-9mr8-pwpw-3j2w"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62909"},{"url":"https://github.com/dotnet/announcements/issues/429"},{"url":"https://github.com/advisories/GHSA-9mr8-pwpw-3j2w"}],"tags":["cve.org","ghsa","nuget"],"epss":0.00288,"epssPercentile":0.21577,"aliases":["GHSA-9mr8-pwpw-3j2w"],"ecosystem":"nuget","patched":["Microsoft.NETCore.App.Runtime.linux-arm 10.0.11","Microsoft.NETCore.App.Runtime.linux-arm64 10.0.11","Microsoft.NETCore.App.Runtime.linux-musl-arm 10.0.11","Microsoft.NETCore.App.Runtime.linux-musl-arm64 10.0.11","Microsoft.NETCore.App.Runtime.linux-musl-x64 10.0.11","Microsoft.NETCore.App.Runtime.linux-x64 10.0.11","Microsoft.NETCore.App.Runtime.osx-arm64 10.0.11","Microsoft.NETCore.App.Runtime.osx-x64 10.0.11","Microsoft.NETCore.App.Runtime.linux-arm 9.0.19","Microsoft.NETCore.App.Runtime.linux-arm64 9.0.19","Microsoft.NETCore.App.Runtime.linux-musl-arm 9.0.19","Microsoft.NETCore.App.Runtime.linux-musl-arm64 9.0.19","Microsoft.NETCore.App.Runtime.linux-musl-x64 9.0.19","Microsoft.NETCore.App.Runtime.linux-x64 9.0.19","Microsoft.NETCore.App.Runtime.osx-arm64 9.0.19","Microsoft.NETCore.App.Runtime.osx-x64 9.0.19","Microsoft.NETCore.App.Runtime.linux-arm 8.0.30","Microsoft.NETCore.App.Runtime.linux-arm64 8.0.30","Microsoft.NETCore.App.Runtime.linux-musl-arm 8.0.30","Microsoft.NETCore.App.Runtime.linux-musl-arm64 8.0.30","Microsoft.NETCore.App.Runtime.linux-musl-x64 8.0.30","Microsoft.NETCore.App.Runtime.linux-x64 8.0.30","Microsoft.NETCore.App.Runtime.osx-arm64 8.0.30","Microsoft.NETCore.App.Runtime.osx-x64 8.0.30"],"scores":{"cna":7.8,"ghsa":6.7},"ingestedAt":"2026-08-11T19:48:29.039Z","slug":"CVE-2026-62909","body":"## Overview\n\nUncaught exception in .NET allows an authorized attacker to elevate privileges locally.\n\n## Affected\n\n- `.net_10.0 >= 10.0.0 < 10.0.11`\n- `.net_8.0 >= 8.0.0 < 8.0.30`\n- `.net_9.0 >= 9.0.0 < 9.0.19`\n- `visual_studio_2022_version_17.14 >= 17.14.0 < 17.14.38`\n- `visual_studio_2026_version_18.8 >= 18.0 < 18.8.3`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-62909)\n\nAffected packages:\n\n- `Microsoft.NETCore.App.Runtime.linux-arm >= 10.0.0, <= 10.0.10`\n- `Microsoft.NETCore.App.Runtime.linux-arm64 >= 10.0.0, <= 10.0.10`\n- `Microsoft.NETCore.App.Runtime.linux-musl-arm >= 10.0.0, <= 10.0.10`\n- `Microsoft.NETCore.App.Runtime.linux-musl-arm64 >= 10.0.0, <= 10.0.10`\n- `Microsoft.NETCore.App.Runtime.linux-musl-x64 >= 10.0.0, <= 10.0.10`\n- `Microsoft.NETCore.App.Runtime.linux-x64 >= 10.0.0, <= 10.0.10`\n- `Microsoft.NETCore.App.Runtime.osx-arm64 >= 10.0.0, <= 10.0.10`\n- `Microsoft.NETCore.App.Runtime.osx-x64 >= 10.0.0, <= 10.0.10`\n- `Microsoft.NETCore.App.Runtime.linux-arm >= 9.0.0, <= 9.0.18`\n- `Microsoft.NETCore.App.Runtime.linux-arm64 >= 9.0.0, <= 9.0.18`\n- `Microsoft.NETCore.App.Runtime.linux-musl-arm >= 9.0.0, <= 9.0.18`\n- `Microsoft.NETCore.App.Runtime.linux-musl-arm64 >= 9.0.0, <= 9.0.18`\n- `Microsoft.NETCore.App.Runtime.linux-musl-x64 >= 9.0.0, <= 9.0.18`\n- `Microsoft.NETCore.App.Runtime.linux-x64 >= 9.0.0, <= 9.0.18`\n- `Microsoft.NETCore.App.Runtime.osx-arm64 >= 9.0.0, <= 9.0.18`\n- `Microsoft.NETCore.App.Runtime.osx-x64 >= 9.0.0, <= 9.0.18`\n- `Microsoft.NETCore.App.Runtime.linux-arm >= 8.0.0, <= 8.0.29`\n- `Microsoft.NETCore.App.Runtime.linux-arm64 >= 8.0.0, <= 8.0.29`\n- `Microsoft.NETCore.App.Runtime.linux-musl-arm >= 8.0.0, <= 8.0.29`\n- `Microsoft.NETCore.App.Runtime.linux-musl-arm64 >= 8.0.0, <= 8.0.29`\n- `Microsoft.NETCore.App.Runtime.linux-musl-x64 >= 8.0.0, <= 8.0.29`\n- `Microsoft.NETCore.App.Runtime.linux-x64 >= 8.0.0, <= 8.0.29`\n- `Microsoft.NETCore.App.Runtime.osx-arm64 >= 8.0.0, <= 8.0.29`\n- `Microsoft.NETCore.App.Runtime.osx-x64 >= 8.0.0, <= 8.0.29`\n\nPatched in:\n\n- `Microsoft.NETCore.App.Runtime.linux-arm 10.0.11`\n- `Microsoft.NETCore.App.Runtime.linux-arm64 10.0.11`\n- `Microsoft.NETCore.App.Runtime.linux-musl-arm 10.0.11`\n- `Microsoft.NETCore.App.Runtime.linux-musl-arm64 10.0.11`\n- `Microsoft.NETCore.App.Runtime.linux-musl-x64 10.0.11`\n- `Microsoft.NETCore.App.Runtime.linux-x64 10.0.11`\n- `Microsoft.NETCore.App.Runtime.osx-arm64 10.0.11`\n- `Microsoft.NETCore.App.Runtime.osx-x64 10.0.11`\n- `Microsoft.NETCore.App.Runtime.linux-arm 9.0.19`\n- `Microsoft.NETCore.App.Runtime.linux-arm64 9.0.19`\n- `Microsoft.NETCore.App.Runtime.linux-musl-arm 9.0.19`\n- `Microsoft.NETCore.App.Runtime.linux-musl-arm64 9.0.19`\n- `Microsoft.NETCore.App.Runtime.linux-musl-x64 9.0.19`\n- `Microsoft.NETCore.App.Runtime.linux-x64 9.0.19`\n- `Microsoft.NETCore.App.Runtime.osx-arm64 9.0.19`\n- `Microsoft.NETCore.App.Runtime.osx-x64 9.0.19`\n- `Microsoft.NETCore.App.Runtime.linux-arm 8.0.30`\n- `Microsoft.NETCore.App.Runtime.linux-arm64 8.0.30`\n- `Microsoft.NETCore.App.Runtime.linux-musl-arm 8.0.30`\n- `Microsoft.NETCore.App.Runtime.linux-musl-arm64 8.0.30`\n- `Microsoft.NETCore.App.Runtime.linux-musl-x64 8.0.30`\n- `Microsoft.NETCore.App.Runtime.linux-x64 8.0.30`\n- `Microsoft.NETCore.App.Runtime.osx-arm64 8.0.30`\n- `Microsoft.NETCore.App.Runtime.osx-x64 8.0.30`\n\nSource: https://github.com/advisories/GHSA-9mr8-pwpw-3j2w","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":8196,"id":"CVE-2026-62909","ts":1788919979611,"field":"cvss","old":"6.7","new":"7.8"},{"seq":8195,"id":"CVE-2026-62909","ts":1788919979611,"field":"severity","old":"medium","new":"high"},{"seq":8005,"id":"CVE-2026-62909","ts":1788919278973,"field":"cvss","old":"7.8","new":"6.7"},{"seq":8004,"id":"CVE-2026-62909","ts":1788919278973,"field":"severity","old":"high","new":"medium"},{"seq":7814,"id":"CVE-2026-62909","ts":1788916338394,"field":"cvss","old":"6.7","new":"7.8"},{"seq":7813,"id":"CVE-2026-62909","ts":1788916338394,"field":"severity","old":"medium","new":"high"},{"seq":7623,"id":"CVE-2026-62909","ts":1788915295701,"field":"cvss","old":"7.8","new":"6.7"},{"seq":7622,"id":"CVE-2026-62909","ts":1788915295701,"field":"severity","old":"high","new":"medium"},{"seq":7432,"id":"CVE-2026-62909","ts":1788912701181,"field":"cvss","old":"6.7","new":"7.8"},{"seq":7431,"id":"CVE-2026-62909","ts":1788912701181,"field":"severity","old":"medium","new":"high"},{"seq":7241,"id":"CVE-2026-62909","ts":1788911329667,"field":"cvss","old":"7.8","new":"6.7"},{"seq":7240,"id":"CVE-2026-62909","ts":1788911329667,"field":"severity","old":"high","new":"medium"},{"seq":7045,"id":"CVE-2026-62909","ts":1788909065810,"field":"cvss","old":"6.7","new":"7.8"},{"seq":7044,"id":"CVE-2026-62909","ts":1788909065810,"field":"severity","old":"medium","new":"high"},{"seq":6857,"id":"CVE-2026-62909","ts":1788907388758,"field":"cvss","old":"7.8","new":"6.7"},{"seq":6856,"id":"CVE-2026-62909","ts":1788907388758,"field":"severity","old":"high","new":"medium"},{"seq":6659,"id":"CVE-2026-62909","ts":1788905432508,"field":"cvss","old":"6.7","new":"7.8"},{"seq":6658,"id":"CVE-2026-62909","ts":1788905432508,"field":"severity","old":"medium","new":"high"},{"seq":6477,"id":"CVE-2026-62909","ts":1788903457426,"field":"cvss","old":"7.8","new":"6.7"},{"seq":6476,"id":"CVE-2026-62909","ts":1788903457426,"field":"severity","old":"high","new":"medium"},{"seq":6272,"id":"CVE-2026-62909","ts":1788901800792,"field":"cvss","old":"6.7","new":"7.8"},{"seq":6271,"id":"CVE-2026-62909","ts":1788901800792,"field":"severity","old":"medium","new":"high"},{"seq":6102,"id":"CVE-2026-62909","ts":1788899560051,"field":"cvss","old":"7.8","new":"6.7"},{"seq":6101,"id":"CVE-2026-62909","ts":1788899560051,"field":"severity","old":"high","new":"medium"},{"seq":5913,"id":"CVE-2026-62909","ts":1788898152650,"field":"cvss","old":"6.7","new":"7.8"},{"seq":5912,"id":"CVE-2026-62909","ts":1788898152650,"field":"severity","old":"medium","new":"high"},{"seq":5802,"id":"CVE-2026-62909","ts":1788895710650,"field":"cvss","old":"7.8","new":"6.7"},{"seq":5801,"id":"CVE-2026-62909","ts":1788895710650,"field":"severity","old":"high","new":"medium"},{"seq":5674,"id":"CVE-2026-62909","ts":1788894526702,"field":"cvss","old":"6.7","new":"7.8"},{"seq":5673,"id":"CVE-2026-62909","ts":1788894526702,"field":"severity","old":"medium","new":"high"},{"seq":5632,"id":"CVE-2026-62909","ts":1788891871020,"field":"cvss","old":"7.8","new":"6.7"},{"seq":5631,"id":"CVE-2026-62909","ts":1788891871020,"field":"severity","old":"high","new":"medium"},{"seq":5611,"id":"CVE-2026-62909","ts":1788890893706,"field":"cvss","old":"6.7","new":"7.8"},{"seq":5610,"id":"CVE-2026-62909","ts":1788890893706,"field":"severity","old":"medium","new":"high"}]}