Integer overflow in Microsoft products - CVE-2026-58641

 

Integer overflow in Microsoft products - CVE-2026-58641

Published: August 12, 2026


Vulnerability identifier: #VU141876
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58641
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to integer overflow or wraparound in .NET when processing crafted local input. A remote attacker can trigger the integer overflow to escalate privileges.

User interaction is required, and successful exploitation could result in SYSTEM privileges.


Affected software

.NET
.NET for Linux
.NET for macOS

How to mitigate CVE-2026-58641

Install security update from vendor's website.

.NET - addressed in versions 8.0.30, 9.0.19
.NET for Linux - addressed in versions 8.0.30, 9.0.19
.NET for macOS - addressed in versions 8.0.30, 9.0.19

External References

Related Security Bulletins