CVE-2026-62897
7
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Summary
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | .NET 10.0 | 10.0.0 < 10.0.11 | affected |
| Microsoft | .NET 8.0 | 8.0.0 < 8.0.30 | affected |
| Microsoft | .NET 9.0 | 9.0.0 < 9.0.19 | affected |
| Microsoft | Microsoft .NET Framework 3.5 | 3.5.0 < 2.0.50727.9183 & 3.0.30729.9169 | affected |
| Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | 4.7.0 < 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0 | affected |
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8 | 4.8.0 < 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0 | affected |
| Microsoft | Microsoft .NET Framework 4.8.1 | 4.8.0.0 < 4.8.9344.0 | affected |
| Microsoft | Microsoft Visual Studio 2022 version 17.14 | 17.14.0 < 17.14.38 | affected |
| Microsoft | Microsoft Visual Studio 2026 version 18.8 | 18.0 < 18.8.3 | affected |
Weaknesses
- CWE-190: CWE-190: Integer Overflow or Wraparound
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.