CVE-2026-32175

EUVD-2026-29571
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories.
To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system.
The security update fixes the vulnerability by ensuring .NET Core properly handles files.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 50.15%
Affected Products (NVD)
VendorProductVersion
microsoftvisual_studio_2022
17.12.0 ≤
𝑥
< 17.12.20
microsoftvisual_studio_2022
17.14.0 ≤
𝑥
< 17.14.32
microsoftvisual_studio_2026
18.5.0 ≤
𝑥
< 18.5.3
microsoft.net
8.0.0 ≤
𝑥
< 8.0.27
microsoft.net
9.0.0 ≤
𝑥
< 9.0.16
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dotnet10
bionic
dne
focal
dne
jammy
dne
noble
not-affected
questing
not-affected
resolute
not-affected
trusty
dne
xenial
dne
dotnet6
bionic
dne
focal
dne
jammy
not-affected
noble
dne
questing
dne
resolute
dne
trusty
dne
xenial
dne
dotnet7
bionic
dne
focal
dne
jammy
ignored
noble
dne
questing
dne
resolute
dne
trusty
dne
xenial
dne
dotnet8
bionic
dne
focal
dne
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
dne
trusty
dne
xenial
dne
dotnet9
bionic
dne
focal
dne
jammy
dne
noble
dne
questing
not-affected
resolute
dne
trusty
dne
xenial
dne