Description
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A heap-based buffer overflow in Microsoft .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. The flaw stems from improper bounds checking during buffer allocation and can be leveraged to execute arbitrary code on the affected system.

Affected Systems

Affected products include Microsoft .NET 8.0, 9.0, 10.0, and 11.0, as well as Microsoft Visual Studio 2022 version 17.14 and Microsoft Visual Studio 2026 version 18.9.

Risk and Exploitability

The CVSS score of 8.8 indicates a severe risk. Exploitation would require network access and the ability to supply crafted input that triggers the overflow. With no EPSS score available and the vulnerability absent from CISA's KEV catalog, public reports of exploitation are unknown, but the high potential impact urges timely mitigation.

Generated by OpenCVE AI on September 8, 2026 at 21:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update that addresses CVE-2026-69439 to all affected .NET runtimes.
  • Upgrade to the most recent release of Microsoft Visual Studio 2022 (17.14+) and Visual Studio 2026 (18.9+), which include the fix.
  • Restrict network access to components that process untrusted data from the network until a patch is applied.

Generated by OpenCVE AI on September 8, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-527h-q9f6-p7qx Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
History

Tue, 29 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows
CPEs cpe:2.3:a:microsoft:.net:11.0.0:preview1:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net:11.0.0:preview2:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net:11.0.0:preview3:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net:11.0.0:preview4:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net:11.0.0:preview5:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net:11.0.0:preview6:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net:11.0.0:preview7:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft windows

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Visual Studio 2022
Microsoft microsoft Visual Studio 2026
Vendors & Products Microsoft microsoft Visual Studio 2022
Microsoft microsoft Visual Studio 2026

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
Title .NET and Visual Studio Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .net Microsoft Visual Studio 2022 Microsoft Visual Studio 2026 Visual Studio 2022 Visual Studio 2026 Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:37:25.599Z

Reserved: 2026-08-03T20:59:32.784Z

Link: CVE-2026-69439

cve-icon Vulnrichment

Updated: 2026-09-09T09:54:17.480Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:07.960

Modified: 2026-09-29T14:05:54.677

Link: CVE-2026-69439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:52:37Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow