---
id: GHSA-2q33-cf8w-7q23
title: 'Duplicate Advisory: Microsoft QUIC Remote Code Execution Vulnerability'
summary: 'Duplicate Advisory: Microsoft QUIC Remote Code Execution Vulnerability'
severity: critical
cvss: 9.8
cwe:
  - CWE-416
vendor: Microsoft
product: Microsoft.Native.Quic.MsQuic.OpenSSL
ecosystem: nuget
affected:
  - Microsoft.Native.Quic.MsQuic.OpenSSL < 2.4.19
published: '2026-08-11'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:26:49Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-2q33-cf8w-7q23'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-62815'
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62815'
  - url: 'https://github.com/advisories/GHSA-2q33-cf8w-7q23'
tags:
  - ghsa
  - nuget
ingestedAt: '2026-09-08T21:11:12.322Z'
---

## Overview

## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-92f5-vc22-8j33. This link is maintained to preserve external references.

## Original Description

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

## Affected packages

- `Microsoft.Native.Quic.MsQuic.OpenSSL < 2.4.19`

## Remediation

Refer to the advisory for the patched release.
