External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
CVE ID: CVE-2025-26646
CVSS Base Severity: HIGH
CVSS Base Score: 8.0
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Vendor: Microsoft
Product: .NET 8.0, .NET 9.0, Microsoft Visual Studio 2022 version 17.12, Microsoft Visual Studio 2022 version 17.13, Microsoft Visual Studio 2022 version 17.8, Microsoft Visual Studio 2022 version 17.10, Build Tools for Visual Studio 2022
EPSS Score: 0.03% (probability of being exploited)
EPSS Percentile: 6.45% (scored less or equal to compared to others)
EPSS Date: 2025-06-03 (when was this score calculated)