Executive brief
.NET and Visual Studio are core development platforms used by organizations to build and run applications. A heap buffer overflow vulnerability in the DiaSymReader component allows attackers to escalate privileges on networked systems, potentially gaining full control of affected machines. An attacker can exploit this flaw remotely by tricking a user into interacting with a malicious input, leading to unauthorized access and potential data compromise or system takeover.
Technical details
This is a heap-based buffer overflow vulnerability (CWE-122) in the Microsoft.DiaSymReader.Native component of .NET and Visual Studio. The flaw resides in dynamic symbol reader functionality used for debugging and symbol resolution. The attack vector is network-based and requires user interaction (UI:R), with no elevated privileges needed for exploitation (PR:N). A successful exploit allows an attacker to read, modify, and disrupt system availability (C:H/I:H/A:H), resulting in elevation of privilege. The vulnerability affects versions from 17.10.0-beta1.24272.1 through 18.9.0-beta1.26405.1; patch version 18.9.0-beta1.26405.2 is available.
Affected products
- Microsoft .NET 17.10.0-beta1.24272.1 through 18.9.0-beta1.26405.1
- Microsoft Visual Studio affected versions correspond to included .NET runtime
- Microsoft Microsoft.DiaSymReader.Native 17.10.0-beta1.24272.1 through 18.9.0-beta1.26405.1
Timeline
- 2026-09-08: disclosed: Published to NVD and GitHub Advisory Database
- 2026-09-09: advisory: Advisory withdrawn as duplicate of GHSA-527h-q9f6-p7qx