Back

HIGH

.NET Framework Remote Code Execution Vulnerability

Published Aug 11, 2026

Description

Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

Affected products

Remediation

Red Hat statement

Red Hat's .NET packages ship only the cross-platform runtime (Microsoft.NETCore.App.Runtime). CVE-2026-62897 affects exclusively Microsoft.WindowsDesktop.App.Runtime.win-* — the WinForms and WPF GUI subsystem for Windows — and is not present in any Red Hat .NET Linux build. Red Hat has never shipped legacy .NET Framework (4.x) either. No Red Hat product is affected.

Red Hat mitigation

No mitigation is required. Red Hat's .NET packages do not ship the Windows Desktop runtime components (Microsoft.WindowsDesktop.App.Runtime) that contain the vulnerability.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Aug 11, 2026
Updated Sep 29, 2026
Reserved Jul 14, 2026
CISA Vulnrichment
Updated Aug 12, 2026
NVD
Status Analyzed
Modified Aug 14, 2026
Red Hat
Severity Important
Public date Aug 11, 2026
GHSA-FX4Q-GJRX-2JW6