Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32175

Опубликовано: 12 мая 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

A flaw was found in dotnet. Improper handling of specially crafted files can cause a path traversal vulnerability in .NET Core, allowing an attacker who can send a malicious file to a vulnerable system to write to arbitrary files and directories in certain locations.

Отчет

This vulnerability can be exploited by an attacker who can send specially crafted files to a vulnerable system. However, the attacker has limited control over the destination of the files and directories that can be accessed, limiting the impact of this flaw. Due to these reasons, this issue has been rated with a moderate severity. This vulnerability affects .NET running on Windows systems. Therefore, Red Hat products are not affected by this issue.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dotnet10.0Not affected
Red Hat Enterprise Linux 10dotnet8.0Not affected
Red Hat Enterprise Linux 10dotnet9.0Not affected
Red Hat Enterprise Linux 8dotnet10.0Not affected
Red Hat Enterprise Linux 8dotnet8.0Not affected
Red Hat Enterprise Linux 8dotnet9.0Not affected
Red Hat Enterprise Linux 9dotnet10.0Not affected
Red Hat Enterprise Linux 9dotnet8.0Not affected
Red Hat Enterprise Linux 9dotnet9.0Not affected
Red Hat Hardened Imagesdotnet10.0Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-36
https://bugzilla.redhat.com/show_bug.cgi?id=2476651dotnet: .NET: improper handling of files allows an attacker to write to certain locations

EPSS

Процентиль: 50%
0.00711
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 месяца назад

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

CVSS3: 4.3
nvd
3 месяца назад

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

CVSS3: 4.3
msrc
3 месяца назад

.NET Core Tampering Vulnerability

CVSS3: 7.5
github
3 месяца назад

Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability

CVSS3: 4.3
fstec
3 месяца назад

Уязвимость программной платформы .NET Core, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю записать произвольные файлы

EPSS

Процентиль: 50%
0.00711
Низкий

4.3 Medium

CVSS3