mediumCVSS 6.7Vulnerability

CVE-2026-62909

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET diagnostics IPC. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A missing error check in .NET causes an improper ACL to be applied to a shared resource, resulting in local elevation of privilege. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/429 ## CVSS Details - **Version:** 3.1 - **Severity:** Medium - **Score:** 6.7 - **Vector:** `CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` - **Weakness:** CWE-252: Unchecked Return Value ## Affected Platforms - **Platforms:** Linux, macOS - **Architectures:** All ## <a name="affected-packages"></a>Affected Packages The vulnerability affects any Microsoft .NET project if it uses any of affected package versions listed below ### <a name=".NET 10"></a>.NET 10 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.NETCore.App.Runtime.linux-arm](https://www.nuget.org/packages/Microsoft.NETCore.App.Runtime.linux-arm) | >= 10.0.0, <= 10.0.10 | 10.0.11 [Microsoft.NETCore.App.Runtime.linux-arm64](https://www.nuget.org/packages/Microsoft.NETCore.App.Runtime.linux-arm64) | >= 10.0.0, <= 10.0.10 | 10.0.11 [Microsoft.NETCore.App.Runtime.linux-musl-arm](https://www.nuget.org/packages/Microsoft.NETCore.App.Runtime.linux-musl-arm) | >= 10.0.0, <= 10.0.10 | 10.0.11 [Microsoft.NETCore.App.Runtime.linux-musl-arm64](https://www.nuget.org/packages/Microsoft.NETCore.App.Runtime.linux-musl-arm64) | >= 10.0.0, <= 10.0.10 | 10.0.11 [Microsoft.NETCore.App.Runtime.linux-musl-x64](https://www.nuget.org/packages/Microsoft.NETCore.App.Runtime.linux-musl-x64) | >= 10.0.0, <= 10.0.10 | 10.0.11 [Microsoft.NETCore.App.Runtime.linux-x64](https://www.nuget.org/packages/Microsoft.NETCore.App.Runtime.linux-x64) | >= 10.0.0, <

Properties

ghsa_id
GHSA-9mr8-pwpw-3j2w
severity
medium
summary
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
cvss_score
6.7
cve_id
CVE-2026-62909
cvss_vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
is_ghsa_only
false
ghsa_published
2026-08-11T19:04:21Z
source_url
https://github.com/advisories/GHSA-9mr8-pwpw-3j2w
ghsa_updated
2026-08-11T19:04:24Z

Related Entities (19)

HAS_WEAKNESS (2)

[Weakness]Unchecked Return Value
[Weakness]Uncaught Exception

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (8)

[Software]nuget/Microsoft.NETCore.App.Runtime.linux-musl-arm64
[Software]nuget/Microsoft.NETCore.App.Runtime.linux-musl-x64
[Software]nuget/Microsoft.NETCore.App.Runtime.linux-musl-arm
[Software]nuget/Microsoft.NETCore.App.Runtime.linux-x64
[Software]nuget/Microsoft.NETCore.App.Runtime.osx-arm64
[Software]nuget/Microsoft.NETCore.App.Runtime.linux-arm
[Software]nuget/Microsoft.NETCore.App.Runtime.osx-x64
[Software]nuget/Microsoft.NETCore.App.Runtime.linux-arm64

AFFECTS (8)

[Software]nuget/Microsoft.NETCore.App.Runtime.linux-musl-arm64
[Software]nuget/Microsoft.NETCore.App.Runtime.osx-arm64
[Software]nuget/Microsoft.NETCore.App.Runtime.linux-arm64
[Software]nuget/Microsoft.NETCore.App.Runtime.linux-x64
[Software]nuget/Microsoft.NETCore.App.Runtime.linux-musl-x64
[Software]nuget/Microsoft.NETCore.App.Runtime.linux-musl-arm
[Software]nuget/Microsoft.NETCore.App.Runtime.osx-x64
[Software]nuget/Microsoft.NETCore.App.Runtime.linux-arm

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-62909 (CVSS 6.7) — Ninja Signal Threat Intelligence | Ninja Signal