File Path Manipulation Vulnerability in .NET by Microsoft
CVE-2026-69805

7.5HIGH

What is CVE-2026-69805?

This vulnerability in .NET enables an unauthorized attacker to manipulate file names or paths, leading to potential privilege escalation over a network. Exploiting this flaw could allow an adversary to execute unauthorized actions, compromising the integrity and security of affected systems.

Affected Version(s)

Microsoft Visual Studio 2022 version 17.14 17.14.0 < 17.14.40

Microsoft Visual Studio 2026 version 18.9 18.9.0 < 18.9.3

Microsoft.Diagnostics.Runtime 4.1.740301

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.