CVE-2026-70354
published 2026-08-11CVE-2026-70354: Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
PriorityP348high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.8th percentile
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_net_framework_3.5 | >= 3.5.0 < 2.0.50727.8984 & 3.0.30729.8980 | 2.0.50727.8984 & 3.0.30729.8980 |
| microsoft | microsoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2 | >= 3.0.0.0 < 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0 | 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0 |
| microsoft | microsoft_net_framework_3.5_and_4.7.2 | >= 4.7.0 < 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0 | 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0 |
| microsoft | microsoft_net_framework_3.5_and_4.8 | >= 4.8.0 < 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0 | 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0 |
| microsoft | microsoft_net_framework_3.5_and_4.8.1 | >= 4.8.1 < 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0 | 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0 |
| microsoft | microsoft_net_framework_4.6.2_4.7_4.7.1_4.7.2 | >= 4.7.0 < 4.7.4144.0 | 4.7.4144.0 |
| microsoft | microsoft_net_framework_4.8 | >= 4.8.0 < 4.8.4805.0 | 4.8.4805.0 |
| microsoft | microsoft_net_framework_4.8.1 | >= 4.8.0.0 < 4.8.9344.0 | 4.8.9344.0 |
| microsoft | microsoft_visual_studio_2022_version_17.14 | >= 17.14.0 < 17.14.38 | 17.14.38 |
| microsoft | microsoft_visual_studio_2026_version_18.8 | >= 18.0 < 18.8.3 | 18.8.3 |
| microsoft | net | >= 10.0.0 < 10.0.11 | 10.0.11 |
| microsoft | net | >= 8.0.0 < 8.0.30 | 8.0.30 |
| microsoft | net | >= 9.0.0 < 9.0.19 | 9.0.19 |
| microsoft | net_10.0 | >= 10.0.0 < 10.0.11 | 10.0.11 |
| microsoft | net_8.0 | >= 8.0.0 < 8.0.30 | 8.0.30 |
| microsoft | net_9.0 | >= 9.0.0 < 9.0.19 | 9.0.19 |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | visual_studio_2022 | >= 17.14.0 < 17.14.38 | 17.14.38 |
| microsoft | visual_studio_2026 | >= 18.8.0 < 18.8.3 | 18.8.3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft .NET/Visual Studio out-of-bounds write
vuldb·2026-08-12·CVSS 7.8
CVE-2026-70354 [HIGH] Microsoft .NET/Visual Studio out-of-bounds write
A vulnerability described as problematic has been identified in Microsoft .NET and Visual Studio. This issue affects some unknown processing. Executing a manipulation can lead to out-of-bounds write.
This vulnerability is handled as CVE-2026-70354. It is possible to launch the attack on the local host. There is not any exploit available.
It is advisable to implement a patch to correct this issue.
GHSA
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
ghsa·2026-08-11·CVSS 7.8
CVE-2026-70354 [HIGH] CWE-787 Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/432
## CVSS Details
- **Version:** 3.1
- **Severity:** High
- **Score:** 7.8
- **Vector:** `CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C`
- **Weakness:** CWE-787: Out-of-bounds Write
## Affected Platforms
- **Platforms:**
Red Hat
dotnet: .NET: Local Code Execution via Out-of-bounds Write
vendor_redhat·2026-08-11·CVSS 7.8
CVE-2026-70354 [HIGH] CWE-787 dotnet: .NET: Local Code Execution via Out-of-bounds Write
dotnet: .NET: Local Code Execution via Out-of-bounds Write
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
A flaw was found in .NET. This vulnerability, caused by an out-of-bounds write, could allow an unauthorized attacker to execute code locally. Exploitation requires local access and user interaction, but if successful, it can lead to significant impact on the system's confidentiality, integrity, and availability.
Statement: Red Hat's .NET packages ship only the cross-platform runtime (Microsoft.NETCore.App.Runtime). CVE-2026-70354 affects exclusively Microsoft.WindowsDesktop.App.Runtime.win-* — the WinForms and WPF GUI subsystem, which is Windows-only and not included in any Red Hat .NET build. No Red Hat product is affected.
Mitigation: No miti
No detection rules found.
No public exploits indexed.
Rapid7
Patch Tuesday - August 2026
blogs_rapid7·2026-08-11·CVSS 7.2
CVE-2026-68821 [HIGH] Patch Tuesday - August 2026
Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month.
## Summary charts
## Summary tables
#
Sans Isc
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
blogs_sans_isc·2026-08-11·CVSS 7.8
CVE-2026-68820 [HIGH] Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
Microsoft Patch Tuesday August 2026
Published: 2026-08-11. Last Updated: 2026-08-11 17:54:49 UTC
by Renato Marinho (Version: 1)
0 comment(s)
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs.
A few vulnerabilities worth mentioning:
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820)
This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancil
Bugzilla
CVE-2026-70354 dotnet: .NET: Local Code Execution via Out-of-bounds Write
bugzilla·2026-08-11·CVSS 7.8
CVE-2026-70354 [HIGH] CVE-2026-70354 dotnet: .NET: Local Code Execution via Out-of-bounds Write
CVE-2026-70354 dotnet: .NET: Local Code Execution via Out-of-bounds Write
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
2026-08-11
Published