Out-of-bounds write in Microsoft products - CVE-2026-70354

 

Out-of-bounds write in Microsoft products - CVE-2026-70354

Published: August 11, 2026


Vulnerability identifier: #VU141498
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-70354
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input in .NET Core. A remote attacker can trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

.NET
Visual Studio
.NET for macOS
.NET for Linux
Microsoft .NET Framework
Fedora
dotnet8.0
dotnet9.0
dotnet10.0

How to mitigate CVE-2026-70354

Install updates from vendor's website.

.NET - addressed in versions 8.0.30, 9.0.19
Visual Studio - update to 17.14.38
Microsoft .NET Framework - addressed in versions 2.0.50727.8984 & 3.0.30729.8980, 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9344.0, 4.7.4144.0, 4.8.4805.0, 10.0.11
.NET for macOS - addressed in versions 8.0.30, 9.0.19
.NET for Linux - addressed in versions 8.0.30, 9.0.19
dotnet8.0 - addressed in versions 8.0.130-1.fc43, 8.0.130-1.fc44
dotnet9.0 - addressed in versions 9.0.120-1.fc43, 9.0.120-1.fc44
dotnet10.0 - addressed in versions 10.0.111-1.fc43, 10.0.111-1.fc44

External References

Related Security Bulletins