Integer overflow in Microsoft products - CVE-2026-62897
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow or wraparound in .NET Framework when processing crafted content locally. A remote attacker can trigger the integer overflow to execute arbitrary code.
User interaction is required for exploitation, and successful exploitation is complex and requires precise conditions.
Affected software
Visual Studio
.NET for macOS
.NET for Linux
Microsoft .NET Framework
How to mitigate CVE-2026-62897
Visual Studio - update to 17.14.38
Microsoft .NET Framework - addressed in versions 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0, 10.0.11
.NET for macOS - addressed in versions 8.0.30, 9.0.19
.NET for Linux - addressed in versions 8.0.30, 9.0.19