[UPDATE] [hoch] Microsoft Entwicklerwerkzeuge: Mehrere Schwachstellen ermöglichen Privilegieneskalation
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in verschiedenen Microsoft Entwicklerwerkzeugen ausnutzen, um seine Privilegien zu erhöhen, um Sicherheitsmechanismen zu umgehen, sowie Informationen zu manipulieren oder offenzulegen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3242
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-341820.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-708730.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-703340.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-784611.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-813570.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-813560.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-813810.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-813800.63% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-784620.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-813790.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownUSN-8740-1: .NET vulnerabilitiesubuntu
- mediumGHSA-8cp2-47hg-mfgh: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerabilityghsa
- highGHSA-2j8r-3c22-8565: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution…ghsa
- highGHSA-527h-q9f6-p7qx: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privileg…ghsa
- highGHSA-63gh-g2x5-x69v: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution…ghsa
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans Microsoft .Net (09 septembre 2026)cert-fr-avis
- unknownMultiples vulnérabilités dans les produits Microsoft (09 septembre 2026)cert-fr-avis
- unknownNCSC-2026-0351 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Developer Toolsncsc-nl
- highCVE-2026-81383: Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized att…nvd
- mediumCVE-2026-81381: Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauth…nvd
- mediumCVE-2026-81380: Improper neutralization of special elements used in a command ('command injection') in GitHub …nvd
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] OpenSSH: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] OpenVPN: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10