Use-after-free in Microsoft products - CVE-2026-62898
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use-after-free in Microsoft QUIC when handling network requests. A remote attacker can send crafted network traffic to disclose sensitive information.
An attacker who successfully exploited this vulnerability could potentially read portions of process memory.
Affected software
Visual Studio
.NET for Linux
.NET for macOS
Microsoft .NET Framework
How to mitigate CVE-2026-62898
Visual Studio - update to 17.14.38
.NET for Linux - addressed in versions 8.0.30, 9.0.19
.NET for macOS - addressed in versions 8.0.30, 9.0.19
Microsoft .NET Framework - update to 10.0.11