CVE-2026-32177

HIGH EPSS 33.3%
Published May 12, 20261mo ago · Modified Jun 19, 20261w ago
7.3 CVSS 3.1
High
Find Similar
Published May 12, 2026 1mo ago
Last Modified Jun 19, 2026 1w ago

Description

Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

CVSS Details

Base Score
7.3
Exploitability
1.8
Impact
5.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity High
Availability Low

Threat Intelligence

EPSS Exploit Probability
33.3% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 3

CWE-122
CWE-20 Improper Input Validation Validation
CWE-787 Out-of-bounds Write Memory Safety

Affected Products 45

VendorProductVersionRange
microsoftvisual_studio_2022*≥17.12.0  –  <17.12.20
microsoftvisual_studio_2022*≥17.14.0  –  <17.14.32
microsoftvisual_studio_2026*≥18.5.0  –  <18.5.3
microsoft.net_framework4.8any
microsoftwindows_10_1607*any
microsoftwindows_server_2012*any
microsoftwindows_server_2012r2any
microsoftwindows_server_2016*any
microsoft.net_framework4.6.2any
microsoft.net_framework4.7any
microsoft.net_framework4.7.1any
microsoft.net_framework4.7.2any
microsoftwindows_server_2012*any
microsoftwindows_server_2012r2any
microsoft.net_framework3.5any
microsoft.net_framework4.8.1any
microsoftwindows_10_21h2*any
microsoftwindows_10_22h2*any
microsoftwindows_10_22h2*any
microsoftwindows_11_22h2*any
microsoftwindows_11_23h2*any
microsoftwindows_11_24h2*any
microsoftwindows_11_24h2*any
microsoftwindows_11_25h2*any
microsoftwindows_11_25h2*any
microsoftwindows_11_26h1*any
microsoftwindows_11_26h1*any
microsoftwindows_server_2022*any
microsoftwindows_server_2025*any
microsoft.net_framework3.5any
microsoft.net_framework4.8any
microsoftwindows_10_1809*any
microsoftwindows_10_1809*any
microsoftwindows_10_21h2*any
microsoftwindows_10_22h2*any
microsoftwindows_10_22h2*any
microsoftwindows_server_2019*any
microsoftwindows_server_2025*any
microsoft.net_framework3.5any
microsoftwindows_server_2012*any
microsoftwindows_server_2012r2any
microsoft.net*≥8.0.0  –  <8.0.27
microsoft.net*≥9.0.0  –  <9.0.16
microsoft.net*≥10.0.0  –  <10.0.8
microsoftwindows*any

References 1

  • msrc.microsoft.com https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32177
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.