highCVSS 8.8Vulnerability

CVE-2026-69439

# Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability ## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Microsoft.DiaSymReader.Native. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An out of bounds write can occur when parsing a Portable PDB file. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/438 ## CVSS Details - **Version:** 3.1 - **Severity:** High - **Score:** 8.8 - **Vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H` - **Weakness:** CWE-122 (Heap-based Buffer Overflow) ## Affected Platforms - **Platforms:** Windows - **Architectures:** All ## <a name="affected-packages"></a>Affected Packages The vulnerability affects any Microsoft .NET project if it uses any of affected package versions listed below ### <a name=".NET 11 RC1"></a>.NET 11 RC1 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.DiaSymReader.Native](https://www.nuget.org/packages/Microsoft.DiaSymReader.Native) | >= 17.10.0-beta1.24272.1, <= 18.9.0-beta1.26405.1 | 18.9.0-beta1.26405.2 ### <a name=".NET 10"></a>.NET 10 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.DiaSymReader.Native](https://www.nuget.org/packages/Microsoft.DiaSymReader.Native) | >= 17.12.0-beta1.24603.5, <= 18.9.0-beta1.26405.1 | 18.9.0-beta1.26405.2 ### <a name=".NET 9"></a>.NET 9 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.DiaSymReader.Native](https://www.nuget.org/packages/Microsoft.DiaSymReader.Native) | >= 17.12.0-beta1.24603.5, <= 18.9.0-beta1.26405.1 | 18.9.0-beta1.26405.2 ### <a name=".NET 8"></a>.NET 8 Package name | Affected version |

Properties

severity
high
summary
Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
epss_score
0.00738
cvss_score
8.8
ghsa_published
2026-09-09T16:03:46Z
source_url
https://github.com/advisories/GHSA-527h-q9f6-p7qx
ghsa_updated
2026-09-09T16:03:47Z
ghsa_id
GHSA-527h-q9f6-p7qx
cve_id
CVE-2026-69439
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
is_ghsa_only
false
epss_percentile
0.52392

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]nuget/Microsoft.DiaSymReader.Native

AFFECTS (1)

[Software]nuget/Microsoft.DiaSymReader.Native

HAS_WEAKNESS (1)

[Weakness]Heap-based Buffer Overflow

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-69439 (CVSS 8.8) — Ninja Signal Threat Intelligence | Ninja Signal