CVE-2026-62897: .NET Framework Remote Code Execution Vulnerability
.NET Framework Remote Code Execution Vulnerability
Other sources
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.8.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.38 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.30Patch KB5122104 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.19Patch KB5122105 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169Patch KB5120747 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.11Patch KB5122106 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9344.0Patch KB5120711 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0Patch KB5120698 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0Patch KB5120703
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62897?
The severity of CVE-2026-62897 is classified as high with a score of 7.
What software is affected by CVE-2026-62897?
CVE-2026-62897 affects Microsoft .NET Framework, Microsoft Visual Studio 2022, Visual Studio 2026, and multiple versions of .NET 8.0 and 9.0 on various operating systems.
How do I fix CVE-2026-62897?
To fix CVE-2026-62897, update the affected Microsoft .NET Framework and Visual Studio products to the latest versions provided by Microsoft.
What type of vulnerability is CVE-2026-62897?
CVE-2026-62897 is an integer overflow vulnerability that enables remote code execution.
What impact does CVE-2026-62897 have?
CVE-2026-62897 allows unauthorized attackers to execute code locally on affected systems.