---
id: GHSA-q72m-f2r4-w4cw
title: >-
  Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and
  Visual Studio Remote Code Execution Vulnerability
summary: >-
  Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and
  Visual Studio Remote Code Execution Vulnerability
severity: high
cvss: 8.8
cwe:
  - CWE-122
vendor: Microsoft
product: Microsoft.DiaSymReader.Native
ecosystem: nuget
affected:
  - >-
    Microsoft.DiaSymReader.Native >= 17.10.0-beta1.24272.1, <=
    18.9.0-beta1.26405.1
patched:
  - Microsoft.DiaSymReader.Native 18.9.0-beta1.26405.2
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T21:06:06Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-q72m-f2r4-w4cw'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-69522'
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69522'
  - url: 'https://github.com/advisories/GHSA-q72m-f2r4-w4cw'
tags:
  - ghsa
  - nuget
ingestedAt: '2026-09-08T21:11:12.320Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-2j8r-3c22-8565. This link is maintained to preserve external references.

### Original Description
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

## Affected packages

- `Microsoft.DiaSymReader.Native >= 17.10.0-beta1.24272.1, <= 18.9.0-beta1.26405.1`

## Remediation

Upgrade to a patched release:

- `Microsoft.DiaSymReader.Native 18.9.0-beta1.26405.2`
