highCVSS 7.8Vulnerability

CVE-2026-62871

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/431 ## CVSS Details - **Version:** 3.1 - **Severity:** High - **Score:** 7.8 - **Vector:** `CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` - **Weakness:** CWE-787: Out-of-bounds Write; CWE-122: Heap-based Buffer Overflow ## Affected Platforms - **Platforms:** Windows - **Architectures:** All ## <a name="affected-packages"></a>Affected Packages The vulnerability affects any Microsoft .NET project if it uses any of affected package versions listed below ### <a name=".NET 10"></a>.NET 10 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.WindowsDesktop.App.Runtime.win-arm64](https://www.nuget.org/packages/Microsoft.WindowsDesktop.App.Runtime.win-arm64) | >= 10.0.0, <= 10.0.10 | 10.0.11 [Microsoft.WindowsDesktop.App.Runtime.win-x64](https://www.nuget.org/packages/Microsoft.WindowsDesktop.App.Runtime.win-x64) | >= 10.0.0, <= 10.0.10 | 10.0.11 [Microsoft.WindowsDesktop.App.Runtime.win-x86](https://www.nuget.org/packages/Microsoft.WindowsDesktop.App.Runtime.win-x86) | >= 10.0.0, <= 10.0.10 | 10.0.11 ### <a name=".NET 9"></a>.NET 9 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.WindowsDesktop.App.Runtime.win-arm64](https://www.nuget.org/packages/Microsoft.WindowsDesktop.App.Runtime.win-arm64) | >= 9.0.0, <= 9.0.18 | 9.0.19 [Microsoft.WindowsDesktop.App.Runtime.win-x64](https://www.nuget.org/packages/Microsoft.WindowsDesktop.App.Runtime.win-x64) | >= 9.0.0,

Properties

ghsa_id
GHSA-vg44-h755-9hw7
severity
high
summary
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
cvss_score
7.8
cve_id
CVE-2026-62871
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
is_ghsa_only
false
ghsa_published
2026-08-11T19:46:40Z
source_url
https://github.com/advisories/GHSA-vg44-h755-9hw7
ghsa_updated
2026-08-11T19:46:40Z

Related Entities (9)

VULNERABLE_TO (3)

[Software]nuget/Microsoft.WindowsDesktop.App.Runtime.win-x86
[Software]nuget/Microsoft.WindowsDesktop.App.Runtime.win-arm64
[Software]nuget/Microsoft.WindowsDesktop.App.Runtime.win-x64

AFFECTS (3)

[Software]nuget/Microsoft.WindowsDesktop.App.Runtime.win-x86
[Software]nuget/Microsoft.WindowsDesktop.App.Runtime.win-x64
[Software]nuget/Microsoft.WindowsDesktop.App.Runtime.win-arm64

HAS_WEAKNESS (2)

[Weakness]Out-of-bounds Write
[Weakness]Heap-based Buffer Overflow

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-62871 (CVSS 7.8) — Ninja Signal Threat Intelligence | Ninja Signal