Microsoft.DiaSymReader.Native
HighNuGetGHSA-q72m-f2r4-w4cw
What to do
Update Microsoft.DiaSymReader.Native to 18.9.0-beta1.26405.2 or later.
dotnet add package Microsoft.DiaSymReader.Native --version 18.9.0-beta1.26405.2
A remote code execution flaw affects the NuGet package Microsoft.DiaSymReader.Native. Affected versions: >= 17.10.0-beta1.24272.1, <= 18.9.0-beta1.26405.1. Fixed from version 18.9.0-beta1.26405.2. CVSS score 8.8.
What the flaw allows: An attacker can make the service run their own code.
- Package
- Microsoft.DiaSymReader.Native
- Ecosystem
- NuGet (.NET)
- Class
- Remote code execution
- Affected versions
- >= 17.10.0-beta1.24272.1, <= 18.9.0-beta1.26405.1
- CVSS
- 8.8
- Published on
- September 8, 2026
Sources
Entry built automatically from the cited security advisory, with no model rewriting. Acknowledged by the organisation or vendor, notified to an authority, or established by two independent sources.