CVE-2026-32175 Details
Description
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.
A tampering vulnerability has been identified in .NET Core, where the framework improperly manages specially crafted files. This vulnerability allows an attacker to write arbitrary files and directories to specific locations on a vulnerable system. However, the attacker would have limited control over where these files and directories are placed. To exploit this vulnerability, an attacker must send a specially crafted file to the affected system.
Users can download the security update for .NET 9.0, .NET 8.0, .NET 10.0, and various versions of Microsoft Visual Studio from the Microsoft Visual Studio Update Center. Instructions for downloading the security update for each product are available on the Microsoft Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32175 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-36 | Absolute Path Traversal | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft visual studio 2022 | >= 17.12.0, < 17.12.20 >= 17.14.0, < 17.14.32 |
CPE
Remediation
| |
| microsoft visual studio 2026 | >= 18.5.0, < 18.5.3 |
CPE
Remediation
| |
| microsoft .net | >= 8.0.0, < 8.0.27 >= 9.0.0, < 9.0.16 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |