Heap-based buffer overflow in Microsoft products - CVE-2026-32177
Published: May 13, 2026
Vulnerability identifier: #VU131324
CSH Severity: Low
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-32177
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to escalate privileges on the target system.
The vulnerability exists due to a boundary error in .NET. A local attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and gain elevated privileges on the system.
Affected software
Microsoft .NET Framework
.NET
Visual Studio
Fedora
dotnet8.0
dotnet9.0
dotnet10.0
.NET
Visual Studio
Fedora
dotnet8.0
dotnet9.0
dotnet10.0
How to mitigate CVE-2026-32177
Install updates from vendor's website.
Microsoft .NET Framework - update to 4.8.9334.0 and 4.8.4802.0
.NET - addressed in versions 8.0.27, 9.0.16
Visual Studio - addressed in versions 15.9.80, 16.11.56, 17.12.20
dotnet8.0 - addressed in versions 8.0.127-1.fc42, 8.0.127-1.fc43, 8.0.127-1.fc44
dotnet9.0 - addressed in versions 9.0.117-1.fc42, 9.0.117-1.fc43, 9.0.117-1.fc44
dotnet10.0 - addressed in versions 10.0.108-1.fc42, 10.0.108-1.fc43, 10.0.108-1.fc44
.NET - addressed in versions 8.0.27, 9.0.16
Visual Studio - addressed in versions 15.9.80, 16.11.56, 17.12.20
dotnet8.0 - addressed in versions 8.0.127-1.fc42, 8.0.127-1.fc43, 8.0.127-1.fc44
dotnet9.0 - addressed in versions 9.0.117-1.fc42, 9.0.117-1.fc43, 9.0.117-1.fc44
dotnet10.0 - addressed in versions 10.0.108-1.fc42, 10.0.108-1.fc43, 10.0.108-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in Microsoft .NET
- Fedora 42 update for dotnet9.0
- Fedora 43 update for dotnet9.0
- Fedora 44 update for dotnet9.0
- Fedora 42 update for dotnet10.0
- Fedora 43 update for dotnet10.0
- Fedora 44 update for dotnet10.0
- Fedora 42 update for dotnet8.0
- Fedora 43 update for dotnet8.0
- Fedora 44 update for dotnet8.0