Out-of-bounds write in Microsoft products - CVE-2026-62871
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code locally.
The vulnerability exists due to out-of-bounds write in .NET when a user triggers the payload in the application. A remote attacker can craft a payload to execute arbitrary code locally.
Successful exploitation could result in SYSTEM privileges. User interaction is required.
Affected software
Visual Studio
.NET for Linux
.NET for macOS
How to mitigate CVE-2026-62871
Visual Studio - update to 17.14.38
.NET for Linux - addressed in versions 8.0.30, 9.0.19
.NET for macOS - addressed in versions 8.0.30, 9.0.19