CVE-2026-32177: .NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
Other sources
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087061 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087055 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087051 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087053 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087054 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087066 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087064 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087065 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087048 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087049 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087058 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087063 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087059 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087068 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087062 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087069 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.5.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.16Patch KB5093448 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9334.0 and 4.8.4802.0Patch KB5087067 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.32 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.12.20 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.8Patch KB5093446 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.27Patch KB5093447
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32177?
CVE-2026-32177 is identified as a high-severity vulnerability due to its potential to allow unauthorized privilege escalation.
How do I fix CVE-2026-32177?
To fix CVE-2026-32177, you should apply the latest security updates provided by Microsoft for the affected .NET Framework versions.
Which versions of .NET Framework are affected by CVE-2026-32177?
CVE-2026-32177 affects .NET Framework versions 3.5 and 4.8.1.
Can CVE-2026-32177 be exploited remotely?
CVE-2026-32177 requires local access for exploitation, meaning an attacker must have physical access to the vulnerable system.
What type of vulnerability is CVE-2026-32177 classified as?
CVE-2026-32177 is classified as a heap-based buffer overflow elevation of privilege vulnerability.