Integer Overflow in.NET Microsoft.WindowsDesktop.App.Runtime
- Severity
- HIGH
- CVSS
- 7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
- Affected component
- Microsoft.WindowsDesktop.App.Runtime.win-arm64 (nuget)
- Affected versions
- >= v9.0.18, <= v9.0.18 or >= v8.0.29, <= v8.0.29 or >= v11.0.0-preview.6, <= v11.0.0-preview.6 or >= v10.0.10, <= v10.0.10 or >= v9.0.17, <= v9.0.17 or >= v11.0.0-preview.5, <= v11.0.0-preview.5 or >= v10.0.9, <= v10.0.9 or >= v8.0.28, <= v8.0.28 or >= v11.0.0-preview.4, <= v11.0.0-preview.4 or >= v9.0.16, <= v9.0.16 or >= v8.0.27, <= v8.0.27 or >= v10.0.8, <= v10.0.8 or >= v10.0.7, <= v10.0.7 or >= v11.0.0-preview.3, <= v11.0.0-preview.3 or >= v10.0.6, <= v10.0.6 or >= v9.0.15, <= v9.0.15 or >= v8.0.26, <= v8.0.26 or >= v10.0.5, <= v10.0.5 or >= v9.0.14, <= v9.0.14 or >= v8.0.25, <= v8.0.25 or >= v11.0.0-preview.2, <= v11.0.0-preview.2 or >= v10.0.4, <= v10.0.4 or >= v11.0.0-preview.1, <= v11.0.0-preview.1 or >= v9.0.13, <= v9.0.13 or >= v8.0.24, <= v8.0.24 or >= v10.0.3, <= v10.0.3 or >= v9.0.12, <= v9.0.12 or >= v8.0.23, <= v8.0.23 or >= v10.0.2, <= v10.0.2 or >= v10.0.1, <= v10.0.1 or >= v9.0.11, <= v9.0.11 or >= v8.0.22, <= v8.0.22 or >= v10.0.0, <= v10.0.0
- Patched version
- 10.0.11
An integer overflow vulnerability in.NET Microsoft.WindowsDesktop.App.Runtime package is under investigation. This affects Microsoft.NET projects using affected versions.
What happened
An integer overflow or wraparound in.NET allows an unauthorized attacker to execute code locally. This affects Microsoft.NET projects using affected versions of the Microsoft.WindowsDesktop.App.Runtime package. The vulnerability is tracked as CVE-2026-62897 and GHSA-FX4Q-GJRX-2JW6. It has not been exploited in the wild.
The affected components are Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, and Microsoft.WindowsDesktop.App.Runtime.win-x86. The affected version ranges are provided in the threat data. The patched versions for each component are also specified.
What to do about it
- Identify if your.NET projects are using affected versions of the Microsoft.WindowsDesktop.App.Runtime package.
- Upgrade to the patched versions of the Microsoft.WindowsDesktop.App.Runtime package for your.NET version.
- Monitor the primary sources for updates on the vulnerability and any additional patches that may be released.
How 0Day would have caught this
Microsoft.WindowsDesktop.App.Runtime.win-arm64 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if your.NET projects are using any of the affected versions of the Microsoft.WindowsDesktop.App.Runtime package as specified in the threat data.
What should I do right now?
Identify if your.NET projects are using affected versions and upgrade to the patched versions as specified in the mitigation steps.
What is the severity of this vulnerability?
The severity of this vulnerability is high, with a CVSS score of 7.