Back to vendor advisories
Microsoft Security Response CenterCVE-2026-70354

.NET Core Remote Code Execution Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

7.8CVSS out of 10High severity
Scope

What the vendor says is affected

  • Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems
  • Microsoft .NET Framework 3.5 on Windows Server 2012
  • Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation)
  • Microsoft .NET Framework 3.5 on Windows 11 Version 26H1 for ARM64-based Systems
  • Microsoft .NET Framework 3.5 on Windows Server 2012 R2
  • Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems
  • Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation)
  • Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems
  • Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems
  • Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016 (Server Core installation)
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019
  • Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019 (Server Core installation)
  • Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation)
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019 (Server Core installation)
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems

Versions the vendor lists as fixed

  • 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0
  • 2.0.50727.8984 & 3.0.30729.8980
  • 2.0.50727.9183 & 3.0.30729.9169
  • 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0
  • 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0
  • 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0
  • 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0
  • 4.7.4144.0
  • 4.8.4805.0
  • 18.8.3
  • 17.14.38
  • 9.0.19
  • 8.0.30
  • 10.0.11
  • 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9344.0
  • 4.8.9344.0
Next step

What the vendor recommends

Install KB5120418. Install KB5120716. Install KB5120747. Install KB5120695. Install KB5120703. Install KB5120698. Install KB5120701. Install KB5120705. Install KB5120709. Install KB5120714. Install KB5120700. Install KB5120699. Install KB5120702. Install KB5120704. Install KB5122105. Install KB5122104. Install KB5122106. Install KB5120708. Install KB5120710. Install KB5120713. Install KB5120706. Install KB5120711.

Review the complete instructions on the vendor's site
Update history

What changed in later vendor updates

SecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.

    • The vendor changed its remediation guidance.
Timeline

When this advisory changed

  1. Published by Microsoft Security Response Center

    The publication date reported by the vendor.

  2. Updated by Microsoft Security Response Center

    The vendor changed the advisory after it was first published.

  3. Added to SecurityAlert

    We collected the advisory from the official source.

  4. Confirmed at the source

    Our collector saw this advisory during a later source check.

Vulnerabilities

CVEs named in this advisory