VYPR
High severity7.0NVD Advisory· Published Aug 11, 2026· Updated Aug 14, 2026

CVE-2026-62897

CVE-2026-62897

Description

Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.WindowsDesktop.App.Runtime.win-arm64NuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.WindowsDesktop.App.Runtime.win-x64NuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.WindowsDesktop.App.Runtime.win-x86NuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.WindowsDesktop.App.Runtime.win-arm64NuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.WindowsDesktop.App.Runtime.win-x64NuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.WindowsDesktop.App.Runtime.win-x86NuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.WindowsDesktop.App.Runtime.win-arm64NuGet
>= 8.0.0, < 8.0.308.0.30
Microsoft.WindowsDesktop.App.Runtime.win-x64NuGet
>= 8.0.0, < 8.0.308.0.30
Microsoft.WindowsDesktop.App.Runtime.win-x86NuGet
>= 8.0.0, < 8.0.308.0.30

Affected products

11
  • cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
    Range: >=8.0.0,<8.0.30
  • cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*
    • (no CPE)
  • cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*range: >=17.14.0,<17.14.38
    • cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*range: >=18.8.0,<18.8.3
  • osv-coords2 versions
    >= 8.0.0, < 8.0.30+ 1 more
    • (no CPE)range: >= 8.0.0, < 8.0.30
    • (no CPE)range: >= 8.0.0, < 8.0.30

Patches

Vulnerability mechanics

References

5

News mentions

3