
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-62909 is a .NET Elevation of Privilege vulnerability caused by an uncaught exception in the .NET diagnostics IPC subsystem. A missing error check causes an improper ACL to be applied to a shared resource, enabling a local attacker with low privileges to escalate to elevated system access. The vulnerability was disclosed on August 11, 2026, as part of Microsoft's August 2026 Patch Tuesday. Affected products include .NET 8.0 (< 8.0.30), .NET 9.0 (< 9.0.19), .NET 10.0 (< 10.0.11), Microsoft Visual Studio 2022 version 17.14 (< 17.14.38), and Microsoft Visual Studio 2026 version 18.8 (< 18.8.3). The CVSS v3.1 base score is 7.8 (High) per Microsoft's advisory, while GitHub's advisory rates it 6.7 (Medium) with slightly different vector assumptions (MSRC Advisory, Github Advisory).
The root cause is classified under CWE-248 (Uncaught Exception) and CWE-252 (Unchecked Return Value). Specifically, a handle truncation error in the ipc_transport_get_default_name function within .NET's diagnostics IPC layer can expose an abstract Unix Domain Socket (UDS) when TMPDIR is excessively long, and a missing return value check causes an improper Access Control List (ACL) to be applied to the resulting shared resource (Github Advisory, bugzilla.redhat.com). The vulnerability affects Linux and macOS platforms across all architectures; Windows is not affected. Exploitation requires local access with low privileges and, per the GitHub advisory's CVSS vector, also requires user interaction, making it a moderate-complexity attack (Github Advisory).
Successful exploitation allows an authorized local user with low privileges to escalate their privileges, potentially gaining full control over the affected system. The CVSS scoring reflects high impacts to confidentiality, integrity, and availability, meaning an attacker could read sensitive data, modify system resources, and disrupt service availability. The scope change indicated in Microsoft's vector suggests the impact can extend beyond the initially compromised component (MSRC Advisory, Github Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The NVD SSVC assessment confirms exploitation is currently "none" and the attack is not automatable. The EPSS score is approximately 0.295%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Microsoft has released patched versions addressing this vulnerability. Users should update to the following fixed versions:
Developers with self-contained applications targeting affected .NET versions must recompile and redeploy their applications after updating the runtime. Visual Studio users will be prompted to update via the IDE, which will also update bundled .NET SDKs. Red Hat Enterprise Linux users should apply the relevant RHSA errata (RHSA-2026:54538 through RHSA-2026:55858) for their respective RHEL versions. Prioritize patching systems where untrusted local users have access (MSRC Advisory, Github Advisory, bugzilla.redhat.com).
The vulnerability was covered as part of broader reporting on Microsoft's August 2026 Patch Tuesday, which addressed approximately 400 flaws. Security outlets including BleepingComputer, CyberSecurityNews, and GBHackers reported on the patch cycle, though CVE-2026-62909 was not individually highlighted as a critical concern given the absence of active exploitation. The vulnerability was acknowledged by researcher Kevin Gosse in Microsoft's advisory credits (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."