Description
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Heap-based buffer overflow in Visual Studio exposes a remote code execution vector. An unauthorized attacker can craft data and send it over a network to trigger memory corruption and arbitrary code execution on the target system. The impact is that the attacker may gain full administrative control of the affected host, enabling tampering with data, installation of malware, or denial of service.

Affected Systems

Affected vendors include Microsoft .NET 10.0, 11.0, 8.0, 9.0 and several .NET Framework releases such as 3.5, 4.6.2 through 4.8.1. The vulnerability also impacts Microsoft Visual Studio 2022 version 17.14 and the upcoming Visual Studio 2026 version 18.9. System administrators should verify that any of these products are present on their infrastructure and that the versions are unpatched.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity, and while the EPSS score is not available, the lack of exploitation data does not diminish the risk of a remote attack. The vulnerability is not yet listed in CISA’s KEV catalog, but the potential for unrestricted code execution warrants immediate remediation. Therefore, organizations should treat this as an urgent risk if the affected software is present in a production environment.

Generated by OpenCVE AI on September 10, 2026 at 02:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for CVE-2026-69522 to all affected .NET Framework, .NET runtime, and Visual Studio installations.
  • Restart any services or systems that host the patched components to ensure the new binaries are loaded.
  • Limit network exposure by adjusting firewall rules to block unnecessary inbound traffic to services that could invoke the vulnerable code paths.

Generated by OpenCVE AI on September 10, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2j8r-3c22-8565 Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
History

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
Title .NET and Visual Studio Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft .net
Microsoft .net Framework
Microsoft visual Studio 2022
Microsoft visual Studio 2026
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
Microsoft .net Framework
Microsoft visual Studio 2022
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .net .net Framework Visual Studio 2022 Visual Studio 2026
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:19.389Z

Reserved: 2026-08-03T21:09:40.782Z

Link: CVE-2026-69522

cve-icon Vulnrichment

Updated: 2026-09-08T19:00:03.828Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-08T18:19:19.697

Modified: 2026-09-09T04:18:56.650

Link: CVE-2026-69522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:00:09Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow