Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-32175

Опубликовано: 12 мая 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
Версия от 17.12.0 (включая) до 17.12.20 (исключая)
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
Версия от 17.14.0 (включая) до 17.14.32 (исключая)
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Версия от 18.5.0 (включая) до 18.5.3 (исключая)
Конфигурация 2

Одновременно

Одно из

cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.0.27 (исключая)
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
Версия от 9.0.0 (включая) до 9.0.16 (исключая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 50%
0.00711
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-36
CWE-22

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 месяца назад

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

CVSS3: 4.3
redhat
3 месяца назад

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

CVSS3: 4.3
msrc
3 месяца назад

.NET Core Tampering Vulnerability

CVSS3: 7.5
github
3 месяца назад

Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability

CVSS3: 4.3
fstec
3 месяца назад

Уязвимость программной платформы .NET Core, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю записать произвольные файлы

EPSS

Процентиль: 50%
0.00711
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-36
CWE-22