.NET Core Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
🎯 Affected products63
- .NET 10.0 installed on Windows
- .NET 8.0 installed on Windows
- .NET 9.0 installed on Windows
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for ARM64-based Systems
- +33 more not shown
✅ Remediation
KB5120418 (Security Update) — fixed build 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0 KB5120716 (Security Update) — fixed build 2.0.50727.8984 & 3.0.30729.8980 KB5120747 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 KB5120695 (Security Update) — fixed build 2.0.50727.8984 & 3.0.30729.8980 KB5120703 (Security Update) — fixed build 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0 KB5120698 (Security Update) — fixed build 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0 KB5120701 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0 KB5120705 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0 KB5120709 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0 KB5120714 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0 KB5120700 (Security Update) — fixed build 4.7.4144.0 KB5120699 (Security Update) — fixed build 4.7.4144.0 KB5120702 (Security Update) — fixed build 4.8.4805.0 KB5120704 (Security Update) — fixed build 4.8.4805.0 Security Update — fixed build 18.8.3 Security Update — fixed build 17.14.38 KB5122105 (Security Update) — fixed build 9.0.19 KB5122104 (Security Update) — fixed build 8.0.30 KB5122106 (Security Update) — fixed build 10.0.11 KB5120708 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9344.0 KB5120710 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0 KB5120713 (Security Update) — fixed build 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0 KB5120706 (Security Update) — fixed build 4.8.4805.0 KB5120711 (Security Update) — fixed build 4.8.9344.0
🔗 References (45)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70354
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120418
- referencehttps://support.microsoft.com/help/5120418
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120716
- referencehttps://support.microsoft.com/help/5120716
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120747
- referencehttps://support.microsoft.com/help/5120747
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120695
- referencehttps://support.microsoft.com/help/5120695
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120703
- referencehttps://support.microsoft.com/help/5120703
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120698
- referencehttps://support.microsoft.com/help/5120698
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120701
- referencehttps://support.microsoft.com/help/5120701
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120705
- referencehttps://support.microsoft.com/help/5120705
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120709
- referencehttps://support.microsoft.com/help/5120709
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120714
- referencehttps://support.microsoft.com/help/5120714
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120700
- referencehttps://support.microsoft.com/help/5120700
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120699
- referencehttps://support.microsoft.com/help/5120699
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120702
- referencehttps://support.microsoft.com/help/5120702
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120704
- referencehttps://support.microsoft.com/help/5120704
- patchhttps://dotnet.microsoft.com/download/dotnet/9.0
- referencehttps://support.microsoft.com/help/5122105
- patchhttps://dotnet.microsoft.com/download/dotnet/8.0
- referencehttps://support.microsoft.com/help/5122104
- patchhttps://dotnet.microsoft.com/download/dotnet/10.0
- referencehttps://support.microsoft.com/help/5122106
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120708
- referencehttps://support.microsoft.com/help/5120708
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120710
- referencehttps://support.microsoft.com/help/5120710
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120713
- referencehttps://support.microsoft.com/help/5120713
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120706
- referencehttps://support.microsoft.com/help/5120706
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120711
- referencehttps://support.microsoft.com/help/5120711