VDB

CVE-2026-32177

CVE-2026-32177 PUBLISHED CVSS 7.300000190734863 HIGH

Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

EPSS 0.10% · 26.5th percentile

Risk Scores

CVSS v3.1
7.300000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C
EPSS Score
0.10%
26.5th percentile

Affected Products

VendorProductVersions
microsoftvisual_studio_201916.11.0, 16.11.0, 16.11.0
MicrosoftMicrosoft .NET Framework 3.53.5.0, 3.5.0, 3.5.0
microsoft.net4.7.0, 4.7.0, 4.8.0
MicrosoftMicrosoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)16.11.0, 16.11.0, 16.11.0
MicrosoftMicrosoft .NET Framework 3.5 AND 4.8.14.8.1, 4.8.1, 4.8.1
Microsoft.NET 8.08.0.0, 8.0.0, 8.0.0
Microsoft.NET 10.010.0.0, 10.0.0, 10.0.0
MicrosoftMicrosoft Visual Studio 2026 version 18.518.5.0, 18.5.0, 18.5.0
MicrosoftMicrosoft .NET Framework 3.5 AND 4.7.24.7.0, 4.7.0, 4.7.0
microsoftvisual_studio_201715.9.0, 15.9.0, 15.9.0
microsoftvisual_studio_202618.5.0, 18.5.0, 18.5.0
microsoftvisual_studio_202217.12.0, 17.14.0, 17.12.0
Microsoft.NET 9.09.0.0, 9.0.0, 9.0.0
MicrosoftMicrosoft .NET Framework 4.6.2/4.7/4.7.1/4.7.24.7.0, 4.7.0, 4.7.0
MicrosoftMicrosoft Visual Studio 2022 version 17.1217.12.0, 17.12.0, 17.12.0
MicrosoftMicrosoft Visual Studio 2022 version 17.1417.14.0, 17.14.0, 17.14.0
MicrosoftMicrosoft .NET Framework 4.84.8.0, 4.8.0, 4.8.0
MicrosoftMicrosoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)15.9.0, 15.9.0, 15.9.0
MicrosoftMicrosoft .NET Framework 3.5 AND 4.84.8.0, 4.8.0, 4.8.0

Timeline

  • May 12, 2026 CVE Published
  • May 12, 2026 PoC Published
  • May 12, 2026 PoC Published
  • May 13, 2026 PoC Published
  • May 13, 2026 PoC Published
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory

References

…and 84 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›