Integer overflow in Microsoft products - CVE-2026-62897

 

Integer overflow in Microsoft products - CVE-2026-62897

Published: August 12, 2026


Vulnerability identifier: #VU141789
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62897
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to integer overflow or wraparound in .NET Framework when processing crafted content locally. A remote attacker can trigger the integer overflow to execute arbitrary code.

User interaction is required for exploitation, and successful exploitation is complex and requires precise conditions.


Affected software

.NET
Visual Studio
.NET for macOS
.NET for Linux
Microsoft .NET Framework

How to mitigate CVE-2026-62897

Install security update from vendor's website.

.NET - addressed in versions 8.0.30, 9.0.19
Visual Studio - update to 17.14.38
Microsoft .NET Framework - addressed in versions 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0, 10.0.11
.NET for macOS - addressed in versions 8.0.30, 9.0.19
.NET for Linux - addressed in versions 8.0.30, 9.0.19

External References

Related Security Bulletins