Back to vendor advisories
Microsoft Security Response CenterCVE-2026-69522

.NET and Visual Studio Remote Code Execution Vulnerability

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

8.8CVSS out of 10High severity
Scope

What the vendor says is affected

  • .NET 10.0 installed on Windows
  • .NET 8.0 installed on Windows
  • .NET 9.0 installed on Windows
  • Microsoft Visual Studio 2022 version 17.14
  • Microsoft .NET Framework 4.8 on Windows Server 2012
  • Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems
  • Microsoft .NET Framework 4.8 on Windows Server 2012 R2
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems
  • Microsoft .NET Framework 4.8 on Windows Server 2016
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for 32-bit Systems
  • Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems
  • Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems
  • Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems
  • Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016
  • Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems

Versions the vendor lists as fixed

  • 10.0.12
  • 8.0.31
  • 9.0.20
  • 17.14.40
  • 4.8.4806.0
  • 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4806.0
  • 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4806.0
  • 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4145.0
  • 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4145.0
  • 4.7.4145.0
  • 4.8.9347.0
  • 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9347.0
  • 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9346.0
  • 18.9.3
  • 11.0 RC1
Next step

What the vendor recommends

Release Notes Install KB5126106. Install KB5126104. Install KB5126105. Install KB5126049. Install KB5126047. Install KB5126051. Install KB5126421. Install KB5126048. Install KB5126050. Install KB5126046. Install KB5126043. Install KB5123099. Install KB5126044. Install KB5126045. Install KB5126053. Install KB5126422. Install KB5126052. Install KB5126424.

Review the complete instructions on the vendor's site
Update history

What changed in later vendor updates

SecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.

    • The vendor changed its remediation guidance.
Timeline

When this advisory changed

  1. Published by Microsoft Security Response Center

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.

Vulnerabilities

CVEs named in this advisory