Integer overflow in Microsoft products - CVE-2026-62886

 

Integer overflow in Microsoft products - CVE-2026-62886

Published: August 12, 2026


Vulnerability identifier: #VU141930
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62886
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to integer overflow or wraparound in .NET when a user triggers the payload in the application. A remote attacker can trigger a crafted payload to escalate privileges.

Successful exploitation could result in SYSTEM privileges. User interaction is required to trigger the payload in the application.


Affected software

.NET
Visual Studio
.NET for Linux
.NET for macOS
Microsoft .NET Framework

How to mitigate CVE-2026-62886

Install security update from vendor's website.

.NET - addressed in versions 8.0.30, 9.0.19
Visual Studio - update to 17.14.38
.NET for Linux - addressed in versions 8.0.30, 9.0.19
.NET for macOS - addressed in versions 8.0.30, 9.0.19
Microsoft .NET Framework - update to 10.0.11

External References

Related Security Bulletins