← Back

CVE-2025-26646

nvd nist
Published: May 13, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.0
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: secure@microsoft.com (Secondary)

Description

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

Affected (7)

3 products
Build Tools
Visual Studio 2022
.net
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Before 17.13.7
Microsoft
From 17.10.0 to 17.10.15
From 17.12.0 to 17.12.8
From 17.13.0 to 17.13.7
From 17.8.0 to 17.8.21
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 9.0.0 to 9.0.5
Configuration C
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
From 8.0.0 to 8.0.16
Running on/withPlatform Versions
Apple
Macos
All versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions

References (1)

Timeline

No history available yet.