CVE-2026-69439: .NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
Other sources
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.9.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.31 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.20 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.40 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.0 RC1
Event History
Frequently Asked Questions
Which systems are in scope for this issue?
The affected software listed is Microsoft Visual Studio 2026, Microsoft Visual Studio 2022, and Microsoft .NET 8.0, 9.0, 10.0, and 11.0 when installed on Windows.
Does exploitation require an authenticated account or local access?
No authentication or prior privileges are required according to the vector, and the attack can be performed over a network. User interaction is required.
What is the likely impact if exploitation succeeds?
Successful exploitation allows an unauthorized attacker to elevate privileges. The supplied severity vector also indicates high impact to confidentiality, integrity, and availability.