Microsoft
Microsoft .net Framework: vulnerabilities and CVEs
Microsoft .net Framework has 202 published vulnerabilities, 25 of them in the last 12 months. 7 are rated critical and 5 are listed by CISA as actively exploited.
CVEs202
Last 12 months25
Critical7
Actively exploited5
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29059 | High (7.5) | 99% | ⚠ Active exploitation | Mar 23, 2024 | .NET Framework Information Disclosure Vulnerability |
| CVE-2015-1671 | High (7.8) | 49% | ⚠ Active exploitation | May 13, 2015 | The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1;… |
| CVE-2020-0646 | Critical (9.8) | 99% | ⚠ Active exploitation | Jan 14, 2020 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'. |
| CVE-2020-1147 | High (7.8) | 94% | ⚠ Active exploitation | Jul 14, 2020 | A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and… |
| CVE-2017-8759 | High (7.8) | 89% | ⚠ Active exploitation | Sep 13, 2017 | Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability." |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-70354 | High (7.8) | 0.36% | — | Aug 11, 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-65810 | High (7.8) | 0.40% | — | Aug 11, 2026 | Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-62897 | High (7) | 0.37% | — | Aug 11, 2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. |
| CVE-2026-62872 | High (8.8) | 0.78% | — | Aug 11, 2026 | Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-50659 | Medium (6.5) | 0.74% | — | Jul 14, 2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-50650 | High (7.8) | 0.46% | — | Jul 14, 2026 | Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-50649 | High (7.8) | 4.0% | — | Jul 14, 2026 | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-50648 | High (7.5) | 1.2% | — | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50646 | High (7.8) | 4.0% | — | Jul 14, 2026 | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. |
| CVE-2026-50527 | High (7.5) | 1.2% | — | Jul 14, 2026 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50525 | High (7.5) | 1.2% | — | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-47304 | Critical (9.8) | 0.29% | — | Jul 14, 2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-47302 | High (7.5) | 1.2% | — | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50647 | High (7.5) | 1.2% | — | Jul 14, 2026 | Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50411 | High (7.5) | 1.2% | — | Jul 14, 2026 | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50368 | High (7.5) | 1.2% | — | Jul 14, 2026 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50355 | High (7.5) | 1.2% | — | Jul 14, 2026 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50653 | High (7.5) | 1.2% | — | Jul 14, 2026 | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50652 | High (7.5) | 1.7% | — | Jul 14, 2026 | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. |
| CVE-2026-35433 | High (7.3) | 0.57% | — | May 12, 2026 | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-32177 | High (7.3) | 0.57% | — | May 12, 2026 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-33116 | High (7.5) | 2.4% | — | Apr 14, 2026 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. |
| CVE-2026-32226 | Medium (5.9) | 0.66% | — | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-23666 | High (7.5) | 1.3% | — | Apr 14, 2026 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2025-55248 | Medium (5.7) | 0.72% | — | Oct 14, 2025 | Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. |
| CVE-2025-21176 | High (8.8) | 2.3% | — | Jan 14, 2025 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability |
| CVE-2024-43484 | High (7.5) | 3.0% | — | Oct 8, 2024 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2024-43483 | High (7.5) | 2.9% | — | Oct 8, 2024 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2024-38081 | High (7.3) | 1.3% | — | Jul 9, 2024 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability |
| CVE-2024-21409 | High (7.3) | 2.5% | — | Apr 9, 2024 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.