A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dotnet8-runtimeUpgrade dotnet9-runtimeUpgrade dotnet10-runtime | May 15, 2026 | May 12, 2026 |
| Microsoft Dot_net | — | Upgrade .NET Runtime 10.0 to laterUpgrade .NET Runtime 8.0 to laterUpgrade .NET Runtime 9.0 to later | Jul 28, 2026 | May 12, 2026 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2022 to the latest version in the current channel channel.Update Microsoft Visual Studio 2026 to the latest version in the current channel channel.Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.12 version stream, or upgrade to a newer supported version of Visual Studio 2022. | May 12, 2026 | May 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub