Out-of-bounds write in Microsoft products - CVE-2026-62871

 

Out-of-bounds write in Microsoft products - CVE-2026-62871

Published: August 12, 2026


Vulnerability identifier: #VU141923
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62871
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code locally.

The vulnerability exists due to out-of-bounds write in .NET when a user triggers the payload in the application. A remote attacker can craft a payload to execute arbitrary code locally.

Successful exploitation could result in SYSTEM privileges. User interaction is required.


Affected software

.NET
Visual Studio
.NET for Linux
.NET for macOS

How to mitigate CVE-2026-62871

Install security update from vendor's website.

.NET - addressed in versions 8.0.30, 9.0.19
Visual Studio - update to 17.14.38
.NET for Linux - addressed in versions 8.0.30, 9.0.19
.NET for macOS - addressed in versions 8.0.30, 9.0.19

External References

Related Security Bulletins