To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system.
The security update fixes the vulnerability by ensuring .NET Core properly handles files.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rg75-q538-x34v | Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability |
Thu, 28 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 20 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* |
Wed, 13 May 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft microsoft Visual Studio 2022
|
|
| Vendors & Products |
Microsoft microsoft Visual Studio 2022
|
Tue, 12 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files. | |
| Title | .NET Core Tampering Vulnerability | |
| First Time appeared |
Microsoft
Microsoft .net Microsoft visual Studio 2017 Microsoft visual Studio 2019 Microsoft visual Studio 2022 Microsoft visual Studio 2026 |
|
| Weaknesses | CWE-36 | |
| CPEs | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft .net Microsoft visual Studio 2017 Microsoft visual Studio 2019 Microsoft visual Studio 2022 Microsoft visual Studio 2026 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-06-19T16:12:35.340Z
Reserved: 2026-03-11T00:26:53.424Z
Link: CVE-2026-32175
Updated: 2026-05-12T19:22:44.313Z
Status : Undergoing Analysis
Published: 2026-05-12T18:16:58.737
Modified: 2026-06-17T10:35:17.383
Link: CVE-2026-32175
OpenCVE Enrichment
Updated: 2026-05-13T10:00:10Z
Github GHSA