Impact
A heap-based buffer overflow in Microsoft .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. The flaw stems from improper bounds checking during buffer allocation and can be leveraged to execute arbitrary code on the affected system.
Affected Systems
Affected products include Microsoft .NET 8.0, 9.0, 10.0, and 11.0, as well as Microsoft Visual Studio 2022 version 17.14 and Microsoft Visual Studio 2026 version 18.9.
Risk and Exploitability
The CVSS score of 8.8 indicates a severe risk. Exploitation would require network access and the ability to supply crafted input that triggers the overflow. With no EPSS score available and the vulnerability absent from CISA's KEV catalog, public reports of exploitation are unknown, but the high potential impact urges timely mitigation.
OpenCVE Enrichment