Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dotnet9-runtimeUpgrade dotnet8-runtimeUpgrade dotnet10-runtime | May 15, 2026 | May 12, 2026 |
| Amazon_linux_2023 | — | Upgrade dotnet-sdk-aot-9.0Upgrade dotnet-hostfxr-10.0-debuginfoUpgrade dotnet-templates-9.0Upgrade dotnet-runtime-10.0Upgrade dotnet-sdk-8.0-debuginfoUpgrade aspnetcore-runtime-9.0Upgrade dotnet-hostfxr-10.0Upgrade dotnet-hostfxr-8.0-debuginfoUpgrade dotnet-runtime-dbg-9.0Upgrade dotnet-sdk-aot-10.0-debuginfoUpgrade dotnet-apphost-pack-9.0Upgrade dotnet-runtime-10.0-debuginfoUpgrade dotnet-apphost-pack-10.0Upgrade dotnet-apphost-pack-10.0-debuginfoUpgrade dotnet-sdk-8.0-source-built-artifactsUpgrade dotnet-apphost-pack-8.0Upgrade dotnet-sdk-10.0-source-built-artifactsUpgrade aspnetcore-targeting-pack-9.0Upgrade dotnet-targeting-pack-10.0Upgrade aspnetcore-runtime-dbg-8.0Upgrade dotnet-sdk-9.0-source-built-artifactsUpgrade dotnet-runtime-8.0Upgrade dotnet8.0-debuginfoUpgrade dotnet-templates-8.0Upgrade dotnet-sdk-dbg-8.0Upgrade dotnet-sdk-9.0-debuginfoUpgrade dotnet-apphost-pack-9.0-debuginfoUpgrade dotnet10.0-debuginfoUpgrade dotnet8.0-debugsourceUpgrade dotnet-sdk-10.0-debuginfoUpgrade aspnetcore-runtime-8.0Upgrade aspnetcore-targeting-pack-8.0Upgrade dotnetUpgrade aspnetcore-runtime-dbg-10.0Upgrade dotnet-hostfxr-9.0Upgrade dotnet-host-debuginfoUpgrade aspnetcore-runtime-dbg-9.0Upgrade dotnet-runtime-dbg-8.0Upgrade dotnet-runtime-9.0-debuginfoUpgrade dotnet-sdk-dbg-10.0Upgrade aspnetcore-runtime-10.0Upgrade dotnet-sdk-10.0Upgrade dotnet9.0-debugsourceUpgrade dotnet-sdk-aot-10.0Upgrade dotnet-runtime-8.0-debuginfoUpgrade dotnet-hostUpgrade aspnetcore-targeting-pack-10.0Upgrade dotnet10.0-debugsourceUpgrade dotnet-hostfxr-8.0Upgrade dotnet-sdk-8.0Upgrade dotnet-runtime-9.0Upgrade netstandard-targeting-pack-2.1Upgrade dotnet-targeting-pack-9.0Upgrade dotnet-sdk-dbg-9.0Upgrade dotnet-templates-10.0Upgrade dotnet-targeting-pack-8.0Upgrade dotnet-runtime-dbg-10.0Upgrade dotnet-hostfxr-9.0-debuginfoUpgrade dotnet-sdk-aot-9.0-debuginfoUpgrade dotnet-sdk-9.0Upgrade dotnet-apphost-pack-8.0-debuginfo | Jun 9, 2026 | May 12, 2026 |
| Microsoft Dot_net | — | Upgrade .NET Runtime 9.0 to laterUpgrade .NET Runtime 10.0 to laterUpgrade .NET Runtime 8.0 to later | Jul 28, 2026 | May 12, 2026 |
| Microsoft Dot_net_framework | — | Apply update KB5087048 for Microsoft .NET Framework 3.5Apply update KB5087064 for Microsoft .NET Framework 3.5\4.8Apply update KB5087049 for Microsoft .NET Framework 3.5Apply update KB5087053 for Microsoft .NET Framework 3.5\4.8.1Apply update KB5087055 for Microsoft .NET Framework 3.5\4.8.1Apply update KB5087065 for Microsoft .NET Framework 4.8Apply update KB5087068 for Microsoft .NET Framework 3.5\4.8Apply update KB5087066 for Microsoft .NET Framework 3.5\4.8Apply update KB5087054 for Microsoft .NET Framework 3.5\4.8.1Apply update KB5087061 for Microsoft .NET Framework 3.5\4.7.2Apply update KB5087069 for Microsoft .NET Framework 4.8Apply update KB5087059 for Microsoft .NET Framework 3.5\4.8.1Apply update KB5087051 for Microsoft .NET Framework 3.5\4.8.1Apply update KB5087058 for Microsoft .NET Framework 3.5\4.8.1Apply update KB5087067 for Microsoft .NET Framework 4.8 | May 12, 2026 | May 12, 2026 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2022 to the latest version in the current channel channel.Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.12 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2026 to the latest version in the current channel channel. | May 12, 2026 | May 12, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 19, 2026 | May 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub