CVE-2026-62871
.NET Elevation of Privilege Vulnerability
Description
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowCVE-2026-62871 is a .NET vulnerability that can let a local attacker run code on a machine using .NET, but it requires someone to interact with a specially made file/component—typical small businesses should patch if you have .NET or Visual Studio installed on systems that untrusted users can access.
A memory-management flaw in the .NET framework (CWE-122/CWE-787) can lead to a local out-of-bounds write that enables arbitrary code execution; exploitation requires no authentication but does require user interaction to process a crafted file/component.
What to do now
- Check whether you run or develop with .NET (including .NET 8.0/.NET 9.0) and which Visual Studio versions are installed (Visual Studio 2022 17.14 or Visual Studio 2026 18.8).
- If you use .NET 8.0, upgrade to .NET 8.0.30 or later.
- If you use .NET 9.0, upgrade to .NET 9.0.19 or later.
- If you use Visual Studio 2022 version 17.14, upgrade to 17.14.38 or later.
- If you use Visual Studio 2026 version 18.8, upgrade to 18.8.3 or later.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62871 and every CVE in our database. Create a free account — no credit card required.
Create Free Account