CVE-2025-26646

Severity
8.0HIGH
EPSS
0.2%
top 53.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 16

Description

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages13 packages

CVEListV5microsoft/build_tools_for_visual_studio_202217.0Fixed Version 17.13.7
NVDmicrosoft/visual_studio_202217.8.017.8.21+3

🔴Vulnerability Details

4
GHSA
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability2025-05-13
OSV
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability2025-05-13
CVEList
.NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability2025-05-13
OSV
CVE-2025-26646: External control of file name or path in2025-05-13

📋Vendor Advisories

4
Ubuntu
.NET vulnerability2025-05-16
Red Hat
dotnet: .NET and Visual Studio Spoofing Vulnerability2025-05-14
Microsoft
.NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability2025-05-13
Microsoft
thermal: intel: hfi: Add syscore callbacks for system-wide PM2024-03-12