External Control of File Name or Path in Microsoft products - CVE-2025-26646
Published: May 13, 2025
Vulnerability identifier: #VU109148
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-26646
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Microsoft
Affected software:
.NET
Build Tools for Visual Studio
.NET for Linux
.NET for macOS
Visual Studio
.NET
Build Tools for Visual Studio
.NET for Linux
.NET for macOS
Visual Studio
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise th target system.
The vulnerability exists due to external control of file name or path in .NET, Visual Studio and Build Tools for Visual Studio. A remote user can perform spoofing attack on the system.
How to mitigate CVE-2025-26646
Install updates from vendor's website.