VDB

CVE-2026-32175

CVE-2026-32175 PUBLISHED CVSS 4.300000190734863 MEDIUM

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

EPSS 0.03% · 9.7th percentile

Risk Scores

CVSS v3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C
EPSS Score
0.03%
9.7th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)15.9.0, 15.9.0, 15.9.0
MicrosoftMicrosoft Visual Studio 2026 version 18.518.5.0, 18.5.0, 18.5.0
microsoft.net8.0.0, 9.0.0, 10.0.0
microsoftvisual_studio_202618.5.0, 18.5.0, 18.5.0
Microsoft.NET 8.08.0.0, 8.0.0, 8.0.0
microsoftvisual_studio_201715.9.0, 15.9.0, 15.9.0
Microsoft.NET 10.010.0.0, 10.0.0, 10.0.0
microsoftvisual_studio_202217.12.0, 17.14.0, 17.14.0
MicrosoftMicrosoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)16.11.0, 16.11.0, 16.11.0
microsoftvisual_studio_201916.11.0, 16.11.0, 16.11.0
MicrosoftMicrosoft Visual Studio 2022 version 17.1417.14.0, 17.14.0, 17.14.0
MicrosoftMicrosoft Visual Studio 2022 version 17.1217.12.0, 17.12.0, 17.12.0
Microsoft.NET 9.09.0.0, 9.0.0, 9.0.0

Timeline

  • May 12, 2026 CVE Published
  • May 12, 2026 PoC Published
  • May 12, 2026 PoC Published
  • May 13, 2026 PoC Published
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory

References

…and 84 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›