Inclusion of Functionality from Untrusted Control Sphere in Microsoft products - CVE-2026-62902

 

Inclusion of Functionality from Untrusted Control Sphere in Microsoft products - CVE-2026-62902

Published: August 12, 2026


Vulnerability identifier: #VU141793
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62902
CWE-ID: CWE-829
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information over a network.

The vulnerability exists due to inclusion of functionality from untrusted control sphere in .NET when processing untrusted functionality. A remote attacker can trigger the vulnerable behavior to disclose sensitive information over a network.

User interaction is required to exploit the issue, and successful exploitation could disclose NTLM hashes.


Affected software

.NET
Visual Studio
.NET for Linux
.NET for macOS
Fedora
dotnet8.0
dotnet9.0
dotnet10.0

How to mitigate CVE-2026-62902

Install security update from vendor's website.

.NET - addressed in versions 8.0.30, 9.0.19
Visual Studio - update to 17.14.38
.NET for Linux - addressed in versions 8.0.30, 9.0.19
.NET for macOS - addressed in versions 8.0.30, 9.0.19
dotnet8.0 - addressed in versions 8.0.130-1.fc43, 8.0.130-1.fc44
dotnet9.0 - addressed in versions 9.0.120-1.fc43, 9.0.120-1.fc44
dotnet10.0 - addressed in versions 10.0.111-1.fc43, 10.0.111-1.fc44

External References

Related Security Bulletins