Threat Advisory

Microsoft .NET Vulnerability Enables Code Execution Through WPF XAML Parsing

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

CVE-2026-50646 with a CVSS score of 7.8 is a remote code execution vulnerability affecting Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64 and Microsoft.WindowsDesktop.App.Runtime.win-x86 in Windows Presentation Foundation (WPF) in .NET 8, .NET 9 and .NET 10 when parsing specially crafted XAML input. An attacker who successfully exploits this vulnerability could execute arbitrary code in the context of the current user. The vulnerability can be exploited through specially crafted XAML input potentially allowing unauthorized code execution. The business impact of this vulnerability is significant as it could enable data theft or system compromise. Developers are advised to install the latest version of .NET and update vulnerable packages to address the vulnerability.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

CVE-2026-50646 with a CVSS score of 7.8 is a remote code execution vulnerability affecting Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64 and Microsoft.WindowsDesktop.App.Runtime.win-x86 in Windows Presentation Foundation (WPF) in .NET 8, .NET 9 and .NET 10 when parsing specially crafted XAML input. An attacker who successfully exploits this vulnerability could execute arbitrary code in the context of the current user. The vulnerability can be exploited through specially crafted XAML input potentially allowing unauthorized code execution. The business impact of this vulnerability is significant as it could enable data theft or system compromise. Developers are advised to install the latest version of .NET and update vulnerable packages to address the vulnerability.[emaillocker id="1283"]

 

RECOMMENDATIONS:

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-gh2h-rhph-h37g

[/emaillocker]
crossmenu