Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32177

33
FAUCET Score

Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

First published: May 12, 2026Last modified: Jun 19, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 17.12.0, < 17.12.20CPE matchmatch criteria
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:-:*:*
>= 17.14.0, < 17.14.32CPE matchmatch criteria
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:-:*:*
>= 18.5.0, < 18.5.3CPE matchmatch criteria
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
4.8CPE matchmatch criteria
cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*
4.6.2CPE matchmatch criteria
cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
1.8
Impact Score
5.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0055 is in the 42nd percentile among its peer group of 11,621 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (70)

microsoftpatch availablevia msrc
Product: 11676-12099Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-12099Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11650-10816Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11650-10378Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11650-10483Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11676-11931Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-12436Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 2472-10378Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 2472-10483Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-12390Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: .NET 10.0 installed on WindowsFixed in: 10.0.8
View patch
microsoftpatch availablevia msrc
Product: .NET 8.0 installed on WindowsFixed in: 8.0.27
View patch
microsoftpatch availablevia msrc
Product: .NET 9.0 installed on WindowsFixed in: 9.0.16
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.12Fixed in: 17.12.20
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.14Fixed in: 17.14.32
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2026 version 18.5Fixed in: 18.5.3
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 4.8 on Windows Server 2016Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 4.8 on Windows Server 2012Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 4.8 on Windows Server 2012 R2Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for x64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for ARM64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 26H1 for x64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 26H1 for ARM64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for x64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 on Windows Server 2012Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 on Windows Server 2012 R2Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11676-11569Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11676-11570Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11676-11571Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11676-11923Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11676-12097Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11676-12098Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11677-11569Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-11923Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11677-11571Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11863-10378Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-12086Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-12243Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-20437Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-20438Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-21196Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-20853Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-20854Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11650-10853Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11677-11570Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-11930Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-12097Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-12389Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 11863-10483Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: 12079-12098Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based SystemsFixed in: 4.8.9334.0 and 4.8.4802.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019Fixed in: 4.8.9334.0 and 4.8.4802.0
View patch

Vendor Advisories (1)

microsoft2026-May/CVE-2026-32177Important

.NET Elevation of Privilege Vulnerability

May 12, 2026

References

access.redhat.com / security/cve/CVE-2026-32177
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-32177.json
msrc.microsoft.com / update-guide/vulnerability/CVE-2026-32177
Vendor Advisory