CVE-2026-62897HighCVSS 7.0

.NET Framework Remote Code Execution Vulnerability

Published
August 14, 2026
Last Modified

🔗 CVE IDs covered (1)

📋 Description

Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

🎯 Affected products11

  • .NET 10.0 installed on Windows
  • .NET 8.0 installed on Windows
  • .NET 9.0 installed on Windows
  • Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems
  • Microsoft .NET Framework 3.5 on Windows 11 Version 26H1 for ARM64-based Systems
  • Microsoft .NET Framework 3.5 on Windows 11 version 26H1 for x64-based Systems
  • Microsoft .NET Framework 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems
  • Microsoft .NET Framework 4.8.1 on Windows 11 version 26H1 for x64-based Systems
  • Microsoft Visual Studio 2022 version 17.14
  • Microsoft Visual Studio 2026 version 18.8

✅ Remediation

KB5120711 (Security Update) — fixed build 4.8.9344.0 KB5120747 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 KB5122106 (Security Update) — fixed build 10.0.11 KB5122104 (Security Update) — fixed build 8.0.30 KB5122105 (Security Update) — fixed build 9.0.19 Security Update — fixed build 18.8.3 Security Update — fixed build 17.14.38 KB5120703 (Security Update) — fixed build 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0 KB5120698 (Security Update) — fixed build 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0

🔗 References (15)