External Control of File Name or Path in Visual Studio - CVE-2026-69805
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to elevate privileges.
The vulnerability exists due to external control of file name or path in .NET when handling externally controlled file names or paths. A remote attacker can win a race condition involving an externally controlled file name or path to elevate privileges.
User interaction is required for exploitation.