← Back

CVE-2026-32175

nvd nist
Published: May 12, 2026Modified: Jun 18, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: secure@microsoft.com (Secondary)

Description

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

Affected (5)

3 products
Visual Studio 2022
Visual Studio 2026
.net
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
From 17.12.0 to 17.12.20
From 17.14.0 to 17.14.32
From 18.5.0 to 18.5.3
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Microsoft
From 8.0.0 to 8.0.27
From 9.0.0 to 9.0.16
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (1)

Timeline

No history available yet.