CVE-2026-62886: .NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
Other sources
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.30Patch KB5122104 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.38 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.11Patch KB5122106 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.19Patch KB5122105 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.8.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62886?
The severity of CVE-2026-62886 is rated as high with a score of 7.8.
How does CVE-2026-62886 impact .NET applications?
CVE-2026-62886 allows an unauthorized attacker to elevate privileges locally through an integer overflow or wraparound vulnerability in .NET.
What software versions are affected by CVE-2026-62886?
CVE-2026-62886 affects Microsoft .NET 8.0, 9.0, and 10.0, installed on various operating systems including Windows, Linux, and Mac OS.
How can I fix CVE-2026-62886?
To fix CVE-2026-62886, ensure you update to the latest version of Microsoft .NET that addresses the vulnerability.
Is CVE-2026-62886 an easy vulnerability to exploit?
CVE-2026-62886 can be exploited with low complexity, making it a significant risk for systems running affected versions of .NET.