Description
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds write in the .NET runtime allows an attacker to execute code locally on the affected system. This flaw can lead to compromise of confidentiality, integrity, and availability of the system as the attacker may gain arbitrary code execution capabilities. The vulnerability is a memory corruption flaw (CWE-787).

Affected Systems

Microsoft .NET 10.0, .NET 8.0, .NET 9.0, Microsoft .NET Framework 3.5, 4.6.2/4.7/4.7.1/4.7.2, 4.8, 4.8.1 and Visual Studio 2022 version 17.14 as well as Visual Studio 2026 version 18.8 are listed as affected. Those products should be checked against the latest cumulative update releases to determine if they include the fix.

Risk and Exploitability

The CVSS score for this vulnerability is 7.8, indicating a high severity. EPSS is reported as < 1%, showing that the modeled probability of exploitation is very low at the present time and the vulnerability is not in the CISA KEV catalog. The attack vector is local; an attacker must be able to supply malicious input or load code into a .NET application. Based on the description, it is inferred that exploitation requires the ability to execute or load untrusted code within the .NET Runtime. Proper patching is therefore critical to mitigate this local code‑execution risk.

Generated by OpenCVE AI on August 12, 2026 at 19:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update that addresses CVE-2026-70354 for the affected .NET Runtime.
  • When patching is not immediately available, isolate applications that run untrusted code or run them with the minimum privileges needed.
  • Monitor the system for anomalous memory writes or crashes in the .NET Runtime and investigate any such events promptly.

Generated by OpenCVE AI on August 12, 2026 at 19:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gg8c-3338-xw2f Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
History

Mon, 17 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
CPEs cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.8.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_11_23h2:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:-:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Visual Studio 2022
Microsoft microsoft Visual Studio 2026
Vendors & Products Microsoft microsoft Visual Studio 2022
Microsoft microsoft Visual Studio 2026

Wed, 12 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Title .NET Core Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft .net
Microsoft .net Framework
Microsoft visual Studio 2022
Microsoft visual Studio 2026
Weaknesses CWE-787
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
Microsoft .net Framework
Microsoft visual Studio 2022
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .net .net Framework Microsoft Visual Studio 2022 Microsoft Visual Studio 2026 Visual Studio 2022 Visual Studio 2026 Windows Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 23h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:08:00.453Z

Reserved: 2026-08-04T00:04:56.037Z

Link: CVE-2026-70354

cve-icon Vulnrichment

Updated: 2026-08-12T16:10:53.188Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:12.640

Modified: 2026-08-17T12:56:51.697

Link: CVE-2026-70354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:30:31Z

Weaknesses