CVE-2025-26646 is a high-severity vulnerability (CVSS 8.0) affecting .NET, Visual Studio, and Build Tools for Visual Studio, allowing an authorized attacker to perform spoofing over a network through external control of file names or paths. This vulnerability has a network attack vector, low attack complexity, and can lead to high impacts on confidentiality, integrity, and availability. While not currently in the KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, including a mention in a BleepingComputer article regarding Microsoft's May 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.13.7CPE matchmatch criteria | cpe:2.3:a:microsoft:build_tools:*:*:*:*:*:visual_studio:*:* | ||
>= 17.8.0, < 17.8.21CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.10.0, < 17.10.15CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.12.0, < 17.12.8CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.13.0, < 17.13.7CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
dotnet: .NET and Visual Studio Spoofing Vulnerability
May 14, 2025Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
May 13, 2025.NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability
May 13, 2025