CVE-2026-62872: .NET Framework Elevation of Privilege Vulnerability
.NET Framework Elevation of Privilege Vulnerability
Other sources
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.4144.0Patch KB5120699 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0Patch KB5120418 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.4144.0Patch KB5120700 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9344.0Patch KB5120711 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0Patch KB5120698 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0Patch KB5120701 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0Patch KB5120703 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4805.0Patch KB5120702 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4805.0Patch KB5120706 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9344.0Patch KB5120708 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0Patch KB5120709 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0Patch KB5120705 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4805.0Patch KB5120704 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8984 & 3.0.30729.8980Patch KB5120716 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169Patch KB5120747 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8984 & 3.0.30729.8980Patch KB5120695 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0Patch KB5120710 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0Patch KB5120713 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0Patch KB5120714
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62872?
CVE-2026-62872 has a severity rating of high, with a score of 8.8.
How do I fix CVE-2026-62872?
To fix CVE-2026-62872, ensure that you apply the latest security updates and patches provided by Microsoft for the .NET Framework.
What type of vulnerability is CVE-2026-62872?
CVE-2026-62872 is classified as an Elevation of Privilege vulnerability.
Who is affected by CVE-2026-62872?
CVE-2026-62872 affects authorized users of the Microsoft .NET Framework who could exploit the vulnerability to elevate their privileges over a network.
What impact does CVE-2026-62872 have on systems?
CVE-2026-62872 can allow an authorized attacker to gain higher privileges than intended, potentially compromising system security.