CVE-2025-26646
published 2025-05-13CVE-2025-26646: External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a…
PriorityP345high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
1.10%
62.0th percentile
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | build_tools | < 17.13.7 | 17.13.7 |
| microsoft | build_tools_for_visual_studio_2022 | >= 17.0 < Fixed Version 17.13.7 | Fixed Version 17.13.7 |
| microsoft | microsoft_visual_studio_2022_version_17.10 | >= 17.10.0 < 17.10.15 | 17.10.15 |
| microsoft | microsoft_visual_studio_2022_version_17.12 | >= 17.12.0 < 17.12.8 | 17.12.8 |
| microsoft | microsoft_visual_studio_2022_version_17.13 | >= 17.13.0 < 17.13.7 | 17.13.7 |
| microsoft | microsoft_visual_studio_2022_version_17.8 | >= 17.8.0 < 17.8.21 | 17.8.21 |
| microsoft | net | >= 8.0.0 < 8.0.16 | 8.0.16 |
| microsoft | net | >= 9.0.0 < 9.0.5 | 9.0.5 |
| microsoft | net_8.0 | >= 8.0.0 < 8.0.16 | 8.0.16 |
| microsoft | net_9.0 | >= 9.0.0 < 9.0.5 | 9.0.5 |
| microsoft | visual_studio_2022 | >= 17.10.0 < 17.10.15 | 17.10.15 |
| microsoft | visual_studio_2022 | >= 17.12.0 < 17.12.8 | 17.12.8 |
| microsoft | visual_studio_2022 | >= 17.13.0 < 17.13.7 | 17.13.7 |
| microsoft | visual_studio_2022 | >= 17.8.0 < 17.8.21 | 17.8.21 |
| msrc | build_tools_for_visual_studio_2022 | — | — |
| msrc | cbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.10 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.12 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.13 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.8 | — | — |
| msrc | net_8.0_installed_on_linux | — | — |
| msrc | net_8.0_installed_on_mac_os | — | — |
| msrc | net_8.0_installed_on_windows | — | — |
| msrc | net_9.0_installed_on_linux | — | — |
| msrc | net_9.0_installed_on_mac_os | — | — |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
ghsa8.0HIGH
osv8.0HIGH
vendor_msrc8.0HIGH
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
ghsa·2025-05-13·CVSS 8.0
CVE-2025-26646 [HIGH] CWE-73 Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
# Microsoft Security Advisory CVE-2025-26646: .NET Spoofing Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0.xxx and .NET 8.0.xxx SDK. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.
A vulnerability exists in .NET SDK or MSBuild applications where external control of file name or path allows an unauthorized attacked to perform spoofing over a network.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/356
### Mitigation factors
Projects which do not utilize the [DownloadFile](https://learn.microsoft.com/visualst
OSV
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
osv·2025-05-13·CVSS 8.0
CVE-2025-26646 [HIGH] Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
# Microsoft Security Advisory CVE-2025-26646: .NET Spoofing Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0.xxx and .NET 8.0.xxx SDK. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.
A vulnerability exists in .NET SDK or MSBuild applications where external control of file name or path allows an unauthorized attacked to perform spoofing over a network.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/356
### Mitigation factors
Projects which do not utilize the [DownloadFile](https://learn.microsoft.com/visualst
OSV
CVE-2025-26646: External control of file name or path in
osv·2025-05-13·CVSS 8.0
CVE-2025-26646 [HIGH] CVE-2025-26646: External control of file name or path in
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
Ubuntu
.NET vulnerability
vendor_ubuntu·2025-05-16
CVE-2025-26646 .NET vulnerability
Title: .NET vulnerability
Summary: .NET could be used to perform spoofing over a network.
It was discovered that .NET did not properly handle file names and paths
under certain conditions. An attacker could possibly use this issue to
perform spoofing over a network.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dotnet: .NET and Visual Studio Spoofing Vulnerability
vendor_redhat·2025-05-14·CVSS 8.0
CVE-2025-26646 [HIGH] CWE-290 dotnet: .NET and Visual Studio Spoofing Vulnerability
dotnet: .NET and Visual Studio Spoofing Vulnerability
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
A flaw was found in .NET and Visual Studio. This vulnerability allows an attacker to use specially crafted input to spoof trusted content or identities, potentially misleading users or systems. This issue requires user interaction and limited privileges but can lead to unauthorized actions or escalation due to incorrect identity or content validation handling.
Statement: This vulnerability in .NET is Important because it allows spoofing of trusted identities or content through crafted input, exploiting weaknesses in validation logic. While it requires user interaction and li
Microsoft
.NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability
vendor_msrc·2025-05-13·CVSS 8.0
CVE-2025-26646 [HIGH] CWE-73 .NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability
.NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability
Description: External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required is low (PR:L). What does that mean for this vulnerability?
An authorized attacker with standard user privileges could place a malicious file and then wait for the privileged victim to run the calling command.
.NET, Visual Studio, and Build Tools for Visual Studio: .NET, Visual Studio, and Build Tools for Visual Studio
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest
Microsoft
thermal: intel: hfi: Add syscore callbacks for system-wide PM
vendor_msrc·2024-03-12·CVSS 5.5
CVE-2024-26646 [MEDIUM] CWE-770 thermal: intel: hfi: Add syscore callbacks for system-wide PM
thermal: intel: hfi: Add syscore callbacks for system-wide PM
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-26646 dotnet: .NET and Visual Studio Spoofing Vulnerability
bugzilla·2025-05-09·CVSS 8.0
CVE-2025-26646 [HIGH] CVE-2025-26646 dotnet: .NET and Visual Studio Spoofing Vulnerability
CVE-2025-26646 dotnet: .NET and Visual Studio Spoofing Vulnerability
This vulnerability allows an authenticated attacker with limited privileges to spoof or impersonate content or identities within affected .NET and Visual Studio applications, potentially leading to privilege escalation or misinformation.
Affected versions:
.NET 8.0
.NET 9.0
Discussion:
CVE is now Public via https://github.com/dotnet/announcements/issues/356
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:7571 https://access.redhat.com/errata/RHSA-2025:7571
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:7589 https://access.redhat.com/errata/RHSA-2025:7589
---
This issue has been addressed in the follow
Bleepingcomputer
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
blogs_bleepingcomputer·2025-05-13·CVSS 7.8
[HIGH] Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
## Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
## Lawrence Abrams
Today is Microsoft's May 2025 Patch Tuesday, which includes security updates for 72 flaws, including five actively exploited and two publicly disclosed zero-day vulnerabilities.
This Patch Tuesday also fixes six "Critical" vulnerabilities, five being remote code execution vulnerabilities and another an information disclosure bug.
The number of bugs in each vulnerability category is listed below:
17 Elevation of Privilege Vulnerabilities
2 Security Feature Bypass Vulnerabilities
28 Remote Code Execution Vulnerabilities
15 Information Disclosure Vulnerabilities
7 Denial of Service Vulnerabilities
2 Spoofing Vulnerabilities
This count does not include Azure, Dataverse, Mariner, and Microsof
2025-05-13
Published