Back

HIGH

.NET Elevation of Privilege Vulnerability

Published Aug 11, 2026

Description

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

Affected products

Remediation

Red Hat statement

Red Hat's .NET packages ship only the cross-platform runtime (Microsoft.NETCore.App.Runtime). CVE-2026-62871 affects exclusively Microsoft.WindowsDesktop.App.Runtime.win-* — the WinForms and WPF GUI subsystem, which is Windows-only and not included in any Red Hat .NET build. No Red Hat product is affected.

Red Hat mitigation

No mitigation is required. Red Hat's .NET packages do not ship the Windows Desktop runtime components (Microsoft.WindowsDesktop.App.Runtime) that contain the vulnerability.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Aug 11, 2026
Updated Sep 29, 2026
Reserved Jul 14, 2026
CISA Vulnrichment
Updated Aug 12, 2026
NVD
Status Analyzed
Modified Aug 13, 2026
Red Hat
Severity Important
Public date Aug 11, 2026
GHSA-VG44-H755-9HW7