Home
HIGH: 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 8.0.0 (custom) before 8.0.16
affected
9.0.0 (custom) before 9.0.5
affected
17.0 (custom) before Fixed Version 17.13.7
affected
17.10.0 (custom) before 17.10.15
affected
17.12.0 (custom) before 17.12.8
affected
17.13.0 (custom) before 17.13.7
affected
17.8.0 (custom) before 17.8.21
affected
Description
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
Problem types
CWE-73: External Control of File Name or Path
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26646 (.NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability)