CVE-2026-62909
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
- EPSS probability
- 0.29%
- CWE
- CWE-248, CWE-252
- Published
- 2026-08-11
- Last modified
- 2026-09-16
Affected products
- Microsoft .NET 10.0
- Microsoft .NET 8.0
- Microsoft .NET 9.0
- Microsoft Microsoft Visual Studio 2022 version 17.14
- Microsoft Microsoft Visual Studio 2026 version 18.8
Weakness type
Related vulnerabilities
- CVE-2013-10065 — Sysax Multi-Server <= 6.10 SSHD Key Exchange DoS
- CVE-2025-12423 — Denial of Service - Protocol Manipulation
- CVE-2024-42037 — Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may af
- CVE-2025-53620 — Crashing any Qwik Server
- CVE-2025-0657 — ALC WebCTRL Carrier i-Vu and Gen5 Controllers Array Index out-of-range
- CVE-2023-5038 — Unauthenticated DoS
- CVE-2026-33191 — free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error
- CVE-2026-34752 — Haraka affected by DoS via `__proto__` email header