CVE-2026-69805: .NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
Other sources
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.9.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.740301 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.40
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability is described as exploitable over a network without prior privileges, but it requires user interaction. The available data does not specify the form of interaction required.
What is the potential impact if exploitation succeeds?
A successful attacker may elevate privileges. The supplied severity vector also indicates potential high impact to confidentiality, integrity, and availability.
Which software is identified as affected?
The listed software includes Microsoft.Diagnostics.Runtime, Microsoft Visual Studio 2026, and Microsoft Visual Studio 2022.