CVE-2025-26646

Name
CVE-2025-26646
Description
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26646

Match rules

CPE URI Source package Min version Max version
.net-8.0 >= 8.0.0 < 8.0.16
.net-9.0 >= 9.0.0 < 9.0.5
microsoft-visual-studio-2022-version-17.12 >= 17.0 < 17.12.8
microsoft-visual-studio-2022-version-17.13 >= 17.10 < 17.13.7
microsoft-visual-studio-2022-version-17.8 >= 17.8.0 < 17.8.21
microsoft-visual-studio-2022-version-17.10 >= 17.10 < 17.10.14
build-tools-for-visual-studio-2022 >= 17.0 < Fixed Version 17.13.7
cpe:2.3:a:microsoft:build_tools:*:*:*:*:*:visual_studio:*:* build_tools >= None < 17.13.7
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* visual_studio_2022 >= 17.8.0 < 17.8.21
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* visual_studio_2022 >= 17.10.0 < 17.10.15
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* visual_studio_2022 >= 17.12.0 < 17.12.8
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* visual_studio_2022 >= 17.13.0 < 17.13.7

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
dotnet9-runtime edge-community 9.0.5-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet9-runtime 3.22-community 9.0.5-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet9-runtime 3.21-community 9.0.5-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet8-runtime edge-community 8.0.16-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet8-runtime 3.22-community 8.0.16-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet8-runtime 3.21-community 8.0.16-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed