Microsoft.WindowsDesktop.App.Runtime.win-x64
NuGet13 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting Microsoft.WindowsDesktop.App.Runtime.win-x64page 1 of 1
- CVE-2020-0606HIGHCVSS 8.8EG 8.8fixed in 3.0.2 or 3.1.11, by version range2020-01-14
vulnerable: 3.1.0 ... 3.1.9 (11 versions)
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user…
- CVE-2022-41089HIGHCVSS 7.8EG 7.8fixed in 3.1.32, 6.0.12 or 7.0.1, by version range2022-12-13
vulnerable: 7.0.0
.NET Framework Remote Code Execution Vulnerability
- CVE-2023-24895HIGHCVSS 7.8EG 7.8fixed in 7.0.7 or 6.0.18, by version range2023-06-14
vulnerable: 6.0.0 ... 6.0.9 (17 versions)
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- CVE-2023-33127HIGHCVSS 8.1EG 8.1fixed in 7.0.9 or 6.0.20, by version range2023-07-11
vulnerable: 6.0.0 ... 6.0.9 (19 versions)
.NET and Visual Studio Elevation of Privilege Vulnerability
- CVE-2024-21409HIGHCVSS 7.3EG 7.3fixed in 6.0.29, 8.0.4 or 7.0.18, by version range2024-04-09
vulnerable: 7.0.0 ... 7.0.9 (17 versions)
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- CVE-2026-35433HIGHCVSS 7.3EG 7.3fixed in 8.0.27, 9.0.16 or 10.0.8, by version range2026-05-12
vulnerable: 10.0.0 ... 10.0.7 (8 versions)
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-50646HIGHCVSS 7.8EG 7.8fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
- CVE-2026-50650HIGHCVSS 7.8EG 7.8fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-62871HIGHCVSS 7.8EG 7.8fixed in 10.0.11, 9.0.19 or 8.0.30, by version range2026-08-11
vulnerable: 8.0.0 ... 8.0.8 (29 versions)
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
- CVE-2026-62886HIGHCVSS 7.8EG 7.8fixed in 10.0.11, 9.0.19 or 8.0.30, by version range2026-08-11
vulnerable: 8.0.0 ... 8.0.8 (29 versions)
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-62897HIGHCVSS 7.0EG 7.0fixed in 10.0.11, 9.0.19 or 8.0.30, by version range2026-08-11
vulnerable: 8.0.0 ... 8.0.8 (29 versions)
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
- CVE-2026-62902MEDIUMCVSS 6.5EG 6.5fixed in 10.0.11, 9.0.19 or 8.0.30, by version range2026-08-11
vulnerable: 8.0.0 ... 8.0.8 (29 versions)
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
- CVE-2026-70354HIGHCVSS 7.8EG 7.8fixed in 10.0.11, 9.0.19 or 8.0.30, by version range2026-08-11
vulnerable: 8.0.0 ... 8.0.8 (29 versions)
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Check whether Microsoft.WindowsDesktop.App.Runtime.win-x64 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for Microsoft.WindowsDesktop.App.Runtime.win-x64 CVEs against the assets you own.
Book a Demo →