Impact
An out-of-bounds write in the .NET runtime allows an attacker to execute code locally on the affected system. This flaw can lead to compromise of confidentiality, integrity, and availability of the system as the attacker may gain arbitrary code execution capabilities. The vulnerability is a memory corruption flaw (CWE-787).
Affected Systems
Microsoft .NET 10.0, .NET 8.0, .NET 9.0, Microsoft .NET Framework 3.5, 4.6.2/4.7/4.7.1/4.7.2, 4.8, 4.8.1 and Visual Studio 2022 version 17.14 as well as Visual Studio 2026 version 18.8 are listed as affected. Those products should be checked against the latest cumulative update releases to determine if they include the fix.
Risk and Exploitability
The CVSS score for this vulnerability is 7.8, indicating a high severity. EPSS is reported as < 1%, showing that the modeled probability of exploitation is very low at the present time and the vulnerability is not in the CISA KEV catalog. The attack vector is local; an attacker must be able to supply malicious input or load code into a .NET application. Based on the description, it is inferred that exploitation requires the ability to execute or load untrusted code within the .NET Runtime. Proper patching is therefore critical to mitigate this local code‑execution risk.
OpenCVE Enrichment
Github GHSA