Kaspersky ID:
KLA91205
Detect Date:
08/11/2026
Updated:
08/12/2026

Description

Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, gain privileges, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability in Visual Studio Code can be exploited remotely to obtain sensitive information.
  2. A security feature bypass vulnerability in Visual Studio Code Python Extension can be exploited remotely to bypass security restrictions.
  3. An information disclosure vulnerability in PowerShell can be exploited remotely to obtain sensitive information.
  4. An elevation of privilege vulnerability in .NET can be exploited remotely to gain privileges.
  5. A security feature bypass vulnerability in Visual Studio Code can be exploited remotely to bypass security restrictions.
  6. A remote code execution vulnerability in Visual Studio Code can be exploited remotely to execute arbitrary code.
  7. An elevation of privilege vulnerability in PowerShell can be exploited remotely to gain privileges.
  8. An elevation of privilege vulnerability in .NET can be exploited remotely to execute arbitrary code.
  9. An elevation of privilege vulnerability in .NET Framework can be exploited remotely to gain privileges.
  10. A remote code execution vulnerability in .NET Framework can be exploited remotely to execute arbitrary code.
  11. An information disclosure vulnerability in Microsoft QUIC can be exploited remotely to obtain sensitive information.
  12. A security feature bypass vulnerability in .NET can be exploited remotely to bypass security restrictions.
  13. An information disclosure vulnerability in .NET can be exploited remotely to obtain sensitive information.
  14. A denial of service vulnerability in .NET can be exploited remotely to cause denial of service.
  15. A security feature bypass vulnerability in CoPilot Chat can be exploited remotely to bypass security restrictions.
  16. An elevation of privilege vulnerability in GitHub Copilot and Visual Studio Code can be exploited remotely to gain privileges.
  17. A remote code execution vulnerability in Microsoft PowerShell can be exploited remotely to execute arbitrary code.
  18. A security feature bypass vulnerability in Microsoft PowerShell can be exploited remotely to bypass security restrictions.
  19. A remote code execution vulnerability in .NET Core can be exploited remotely to execute arbitrary code.

Original advisories

Exploitation

Related products

CVE list

  • CVE-2026-47285
    unknown
  • CVE-2026-54981
    unknown
  • CVE-2026-58612
    unknown
  • CVE-2026-58641
    unknown
  • CVE-2026-58650
    unknown
  • CVE-2026-59113
    unknown
  • CVE-2026-59119
    unknown
  • CVE-2026-62871
    unknown
  • CVE-2026-62872
    unknown
  • CVE-2026-62886
    unknown
  • CVE-2026-62897
    unknown
  • CVE-2026-62898
    unknown
  • CVE-2026-62899
    unknown
  • CVE-2026-62900
    unknown
  • CVE-2026-62901
    unknown
  • CVE-2026-62902
    unknown
  • CVE-2026-62909
    unknown
  • CVE-2026-65675
    unknown
  • CVE-2026-65810
    unknown
  • CVE-2026-69278
    unknown
  • CVE-2026-69306
    unknown
  • CVE-2026-69320
    unknown
  • CVE-2026-70335
    unknown
  • CVE-2026-70336
    unknown
  • CVE-2026-70337
    unknown
  • CVE-2026-70338
    unknown
  • CVE-2026-70354
    unknown

KB list

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Do you want to save your changes?
Your message has been sent successfully.