VYPR
Medium severity4.3NVD Advisory· Published May 12, 2026· Updated Jun 18, 2026

CVE-2026-32175

CVE-2026-32175

Description

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.NetCore.App.Runtime.win-armNuGet
>= 8.0.0, < 8.0.278.0.27
Microsoft.NetCore.App.Runtime.win-armNuGet
>= 9.0.0, < 9.0.169.0.16
Microsoft.NetCore.App.Runtime.win-armNuGet
>= 10.0.0, < 10.0.810.0.8
Microsoft.NetCore.App.Runtime.win-arm64NuGet
>= 8.0.0, < 8.0.278.0.27
Microsoft.NetCore.App.Runtime.win-arm64NuGet
>= 9.0.0, < 9.0.169.0.16
Microsoft.NetCore.App.Runtime.win-arm64NuGet
>= 10.0.0, < 10.0.810.0.8
Microsoft.NetCore.App.Runtime.win-x64NuGet
>= 8.0.0, < 8.0.278.0.27
Microsoft.NetCore.App.Runtime.win-x64NuGet
>= 9.0.0, < 9.0.169.0.16
Microsoft.NetCore.App.Runtime.win-x64NuGet
>= 10.0.0, < 10.0.810.0.8
Microsoft.NetCore.App.Runtime.win-x86NuGet
>= 8.0.0, < 8.0.278.0.27
Microsoft.NetCore.App.Runtime.win-x86NuGet
>= 9.0.0, < 9.0.169.0.16
Microsoft.NetCore.App.Runtime.win-x86NuGet
>= 10.0.0, < 10.0.810.0.8

Affected products

6
  • cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
    Range: >=8.0.0,<8.0.27
  • cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*range: >=17.12.0,<17.12.20
    • cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*range: >=18.5.0,<18.5.3
  • osv-coords2 versions
    >= 8.0.0, < 8.0.27+ 1 more
    • (no CPE)range: >= 8.0.0, < 8.0.27
    • (no CPE)range: >= 8.0.0, < 8.0.27

Patches

Vulnerability mechanics

References

5

News mentions

2