NUGET · AUGUST 2026 · EARLY WARNING

Integer Overflow in.NET Microsoft.WindowsDesktop.App.Runtime

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
CVSS
7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Affected component
Microsoft.WindowsDesktop.App.Runtime.win-arm64 (nuget)
Affected versions
>= v9.0.18, <= v9.0.18 or >= v8.0.29, <= v8.0.29 or >= v11.0.0-preview.6, <= v11.0.0-preview.6 or >= v10.0.10, <= v10.0.10 or >= v9.0.17, <= v9.0.17 or >= v11.0.0-preview.5, <= v11.0.0-preview.5 or >= v10.0.9, <= v10.0.9 or >= v8.0.28, <= v8.0.28 or >= v11.0.0-preview.4, <= v11.0.0-preview.4 or >= v9.0.16, <= v9.0.16 or >= v8.0.27, <= v8.0.27 or >= v10.0.8, <= v10.0.8 or >= v10.0.7, <= v10.0.7 or >= v11.0.0-preview.3, <= v11.0.0-preview.3 or >= v10.0.6, <= v10.0.6 or >= v9.0.15, <= v9.0.15 or >= v8.0.26, <= v8.0.26 or >= v10.0.5, <= v10.0.5 or >= v9.0.14, <= v9.0.14 or >= v8.0.25, <= v8.0.25 or >= v11.0.0-preview.2, <= v11.0.0-preview.2 or >= v10.0.4, <= v10.0.4 or >= v11.0.0-preview.1, <= v11.0.0-preview.1 or >= v9.0.13, <= v9.0.13 or >= v8.0.24, <= v8.0.24 or >= v10.0.3, <= v10.0.3 or >= v9.0.12, <= v9.0.12 or >= v8.0.23, <= v8.0.23 or >= v10.0.2, <= v10.0.2 or >= v10.0.1, <= v10.0.1 or >= v9.0.11, <= v9.0.11 or >= v8.0.22, <= v8.0.22 or >= v10.0.0, <= v10.0.0
Patched version
10.0.11
CVE-2026-62897GHSA-FX4Q-GJRX-2JW6

An integer overflow vulnerability in.NET Microsoft.WindowsDesktop.App.Runtime package is under investigation. This affects Microsoft.NET projects using affected versions.

What happened

An integer overflow or wraparound in.NET allows an unauthorized attacker to execute code locally. This affects Microsoft.NET projects using affected versions of the Microsoft.WindowsDesktop.App.Runtime package. The vulnerability is tracked as CVE-2026-62897 and GHSA-FX4Q-GJRX-2JW6. It has not been exploited in the wild.

The affected components are Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, and Microsoft.WindowsDesktop.App.Runtime.win-x86. The affected version ranges are provided in the threat data. The patched versions for each component are also specified.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If Microsoft.WindowsDesktop.App.Runtime.win-arm64 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if your.NET projects are using any of the affected versions of the Microsoft.WindowsDesktop.App.Runtime package as specified in the threat data.

What should I do right now?

Identify if your.NET projects are using affected versions and upgrade to the patched versions as specified in the mitigation steps.

What is the severity of this vulnerability?

The severity of this vulnerability is high, with a CVSS score of 7.

Sources

Join the 0Day waitlist →

← Back to all threats