Inclusion of Functionality from Untrusted Control Sphere in Microsoft products - CVE-2026-62902
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information over a network.
The vulnerability exists due to inclusion of functionality from untrusted control sphere in .NET when processing untrusted functionality. A remote attacker can trigger the vulnerable behavior to disclose sensitive information over a network.
User interaction is required to exploit the issue, and successful exploitation could disclose NTLM hashes.
Affected software
Visual Studio
.NET for Linux
.NET for macOS
Fedora
dotnet8.0
dotnet9.0
dotnet10.0
How to mitigate CVE-2026-62902
Visual Studio - update to 17.14.38
.NET for Linux - addressed in versions 8.0.30, 9.0.19
.NET for macOS - addressed in versions 8.0.30, 9.0.19
dotnet8.0 - addressed in versions 8.0.130-1.fc43, 8.0.130-1.fc44
dotnet9.0 - addressed in versions 9.0.120-1.fc43, 9.0.120-1.fc44
dotnet10.0 - addressed in versions 10.0.111-1.fc43, 10.0.111-1.fc44