CVE-2026-69805
7.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Summary
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Microsoft Visual Studio 2022 version 17.14 | 17.14.0 < 17.14.40 | affected |
| Microsoft | Microsoft Visual Studio 2026 version 18.9 | 18.9.0 < 18.9.3 | affected |
| Microsoft | Microsoft.Diagnostics.Runtime | 4.1.740301 < 4.1.740301 | affected |
Weaknesses
- CWE-73: CWE-73: External Control of File Name or Path
- CWE-522: CWE-522: Insufficiently Protected Credentials
- CWE-200: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.