---
id: GHSA-mqvm-gmc4-6rv2
title: >-
  Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and
  Visual Studio Elevation of Privilege Vulnerability
summary: >-
  Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and
  Visual Studio Elevation of Privilege Vulnerability
severity: high
cvss: 8.8
cwe:
  - CWE-122
vendor: Microsoft
product: Microsoft.DiaSymReader.Native
ecosystem: nuget
affected:
  - >-
    Microsoft.DiaSymReader.Native >= 17.10.0-beta1.24272.1, <=
    18.9.0-beta1.26405.1
patched:
  - Microsoft.DiaSymReader.Native 18.9.0-beta1.26405.2
published: '2026-09-08'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:02:53Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-mqvm-gmc4-6rv2'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-69439'
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69439'
  - url: 'https://github.com/advisories/GHSA-mqvm-gmc4-6rv2'
tags:
  - ghsa
  - nuget
ingestedAt: '2026-09-09T16:14:05.560Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-527h-q9f6-p7qx. This link is maintained to preserve external references.

### Original Description
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.

## Affected packages

- `Microsoft.DiaSymReader.Native >= 17.10.0-beta1.24272.1, <= 18.9.0-beta1.26405.1`

## Remediation

Upgrade to a patched release:

- `Microsoft.DiaSymReader.Native 18.9.0-beta1.26405.2`
