CVE-2026-62909: .NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
Other sources
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.19Patch KB5122105 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.11Patch KB5122106 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.30Patch KB5122104 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.38 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.8.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62909?
CVE-2026-62909 has a high severity rating of 7.8.
How do I fix CVE-2026-62909?
To fix CVE-2026-62909, update the affected .NET software to the latest version provided by Microsoft.
What systems are affected by CVE-2026-62909?
CVE-2026-62909 affects Microsoft .NET versions 8.0, 9.0, and 10.0 on Windows, Linux, and Mac OS.
What does CVE-2026-62909 exploit?
CVE-2026-62909 exploits an uncaught exception in .NET that allows an authorized attacker to elevate privileges locally.
Is CVE-2026-62909 being actively exploited?
As of the latest information, there are no reports indicating that CVE-2026-62909 is actively being exploited in the wild.