Description
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in the .NET runtime that permits an attacker with local access to overwrite memory and execute arbitrary code. This flaw effectively grants elevation of privilege, allowing the attacker to gain administrative rights or control over the affected machine. The weakness is a classic buffer overrun (CWE-122 and CWE-787), which compromises integrity and confidentiality of data stored in memory and can lead to denial of service if exploited to crash an application.

Affected Systems

Microsoft releases that contain the vulnerability include the .NET 8.0, 9.0 and 10.0 runtimes, as well as Microsoft Visual Studio 2022 version 17.14 and Microsoft Visual Studio 2026 version 18.8. All instances of these products before the published security update are potentially affected. Users should check the specific build they are running against the advisory and verify whether it contains the fix.

Risk and Exploitability

The CVSS score of 7.8 classifies the issue as high severity, though the EPSS score is not available, so the current exploitation likelihood is unknown but could be realistic for local attackers. The flaw is not listed in CISA KEV, indicating no known widespread exploitation yet. An attacker must have local code execution capabilities, for example by running a malicious DLL or manipulating a data stream processed by an untrusted .NET application, to trigger the overrun and achieve privilege escalation.

Generated by OpenCVE AI on August 12, 2026 at 14:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest .NET runtime security update for CVE-2026-62871 from the Microsoft Security Update Guide.
  • Upgrade Microsoft Visual Studio to the fixed release (17.15 or later for VS 2022, 18.9 or later for VS 2026) or apply the corresponding patch when it becomes available.
  • Ensure applications that use the affected .NET runtime run with the least privileged account and restrict execution of untrusted code to mitigate potential exploitation.

Generated by OpenCVE AI on August 12, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vg44-h755-9hw7 Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Visual Studio 2022
Microsoft microsoft Visual Studio 2026
Vendors & Products Microsoft microsoft Visual Studio 2022
Microsoft microsoft Visual Studio 2026

Thu, 13 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft windows
CPEs cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft windows

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Title .NET Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
Weaknesses CWE-122
CWE-787
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Apple Macos
Linux Linux Kernel
Microsoft .net Microsoft Visual Studio 2022 Microsoft Visual Studio 2026 Visual Studio 2022 Visual Studio 2026 Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:08.254Z

Reserved: 2026-07-14T21:13:55.099Z

Link: CVE-2026-62871

cve-icon Vulnrichment

Updated: 2026-08-12T13:46:22.695Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:37.843

Modified: 2026-08-13T18:17:54.360

Link: CVE-2026-62871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:31:36Z

Weaknesses