Heap-based buffer overflow in Microsoft products - CVE-2026-69439
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute code with the privileges of the affected process.
The vulnerability exists due to a heap-based buffer overflow in .NET and Visual Studio when processing a specially crafted Portable PDB file. A remote attacker can convince a user or service to process a specially crafted Portable PDB file to execute code with the privileges of the affected process.
Affected software
Visual Studio
Microsoft .NET Framework
How to mitigate CVE-2026-69439
Visual Studio - update to 17.14.40
Microsoft .NET Framework - update to 10.0.12