Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2025-26646

Опубликовано: 13 мая 2025
Источник: msrc
CVSS3: 8
EPSS Низкий

Описание

.NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

FAQ

According to the CVSS metric, user interaction is required (UI:R) and privileges required  is low (PR:L). What does that mean for this vulnerability?

An authorized attacker with standard user privileges could place a malicious file and then wait for the privileged victim to run the calling command.

Обновления

ПродуктСтатьяОбновление
Microsoft Visual Studio 2022 version 17.8
Microsoft Visual Studio 2022 version 17.10
.NET 8.0 installed on Windows
.NET 8.0 installed on Linux
.NET 8.0 installed on Mac OS
.NET 9.0 installed on Linux
.NET 9.0 installed on Mac OS
.NET 9.0 installed on Windows
Microsoft Visual Studio 2022 version 17.12
Microsoft Visual Studio 2022 version 17.13

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

DOS

N/A

EPSS

Процентиль: 8%
0.00033
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
ubuntu
около 1 месяца назад

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

CVSS3: 8
redhat
около 1 месяца назад

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

CVSS3: 8
nvd
около 1 месяца назад

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

CVSS3: 8
github
около 1 месяца назад

Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability

oracle-oval
29 дней назад

ELSA-2025-7600: .NET 9.0 security update (IMPORTANT)

EPSS

Процентиль: 8%
0.00033
Низкий

8 High

CVSS3