Executive brief
A security vulnerability exists in the Windows Presentation Foundation (WPF) framework, which is used by developers to build visual interfaces for Windows applications. An attacker could use a specially crafted file to gain higher-level permissions on a user's computer. This could allow an unauthorized person to perform actions they normally wouldn't have permission to do, potentially compromising the security of the entire system.
Technical details
An elevation of privilege vulnerability exists in Windows Presentation Foundation (WPF) within .NET 8, .NET 9, and .NET 10. The issue is classified as a code injection vulnerability (CWE-94) occurring during the parsing of specially crafted XAML input. To exploit this, an attacker would typically need to convince a user to open a malicious file or run a malicious application locally. Successful exploitation allows the attacker to execute code with elevated privileges on the affected Windows system. Microsoft has released patches for .NET 8 (8.0.29), .NET 9 (9.0.18), and .NET 10 (10.0.10) to address this flaw.
Affected products
- Microsoft .NET 8.0.0-8.0.28, 9.0.0-9.0.17, 10.0.0-10.0.9
- Microsoft Windows Presentation Foundation (WPF) .NET 8, .NET 9, .NET 10
Timeline
- 2026-07-14: disclosed: Advisory published by Microsoft
- 2026-07-14: patched: Patched versions released for .NET 8, 9, and 10
- 2026-07-21: advisory: GitHub Advisory reviewed and updated
References
- https://github.com/dotnet/wpf/security/advisories/GHSA-2969-4q4w-w5h3
- https://github.com/dotnet/announcements/issues/421
- https://github.com/dotnet/wpf/issues/11784
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50650
- https://api.github.com/repos/dotnet/wpf/security-advisories/GHSA-2969-4q4w-w5h3