V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2025-26646
MSR
High

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform sp…

CVSS
8.0
High
EPSS
0.01
p60
Published
2025-01-01
Updated
2025-01-01
Description

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

Tags · CWE
CWE-73
CAPEC-13
CAPEC-64
CAPEC-72
CAPEC-76
CAPEC-78
CAPEC-79
CAPEC-80
CAPEC-267
Affected products
Build_tools < 17.13.7Visual_studio_2022 17.8.0–17.8.21Visual_studio_2022 17.10.0–17.10.15Visual_studio_2022 17.12.0–17.12.8Visual_studio_2022 17.13.0–17.13.7
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.011 · p60
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
dotnet6Tracked
dotnet7Tracked
dotnet8Tracked
dotnet8Tracked
dotnet8Tracked
dotnet8Tracked
dotnet8Tracked
dotnet9Tracked
dotnet9Tracked
dotnet9Tracked
.net*Tracked
.net*Tracked
build_tools*Tracked
visual_studio_2022*Tracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked