Impact
A stack-based buffer overflow in the Microsoft .NET Framework can be triggered by an attacker sending specially crafted data over a network. The flaw, identified as CWE‑120 and CWE‑121, allows the attacker to corrupt stack memory and crash the affected component. The resulting crash causes a denial of service for any application or service that relies on the .NET runtime, but no data is disclosed or modified.
Affected Systems
This vulnerability affects Microsoft .NET Framework releases from 3.5 through 4.8.1, as well as the newer 8.0, 9.0, and 10.0 runtimes. It also impacts Visual Studio 2022 build 17.12 and 17.14, and Visual Studio 2026 build 18.7. All installations of these products on any operating system are potentially vulnerable unless the fix has been applied.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, but the EPSS score of < 1% suggests a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploits. Based on the description, it is inferred that the attack vector is remote over a network, requiring an attacker to send malformed input to a vulnerable .NET component. Successful exploitation would cause a crash and deny service to dependent processes, without affecting confidentiality or integrity.
OpenCVE Enrichment
Github GHSA
Ubuntu USN