← CVE catalog

CVE-2026-32175

Medium CVSS 4.3

Published 2026-05-12 ยท last changed 2026-06-18

The fix

Microsoft fixes this in updatesKB5093446, KB5093447, KB5093448. The fixed build differs per Windows version, so the row that matters is the one matching the machine you are looking at.

Windows version Fixed in build Update Released
.NET 10.0 installed on Windows 10.0.8 KB5093446 2026-09-18
.NET 8.0 installed on Windows 8.0.27 KB5093447 2026-09-18
.NET 9.0 installed on Windows 9.0.16 KB5093448 2026-09-18

Having the KB is not the same as knowing whether a machine has it. Windows updates supersede each other, so the update you installed often covers a fix that shipped in an earlier one. Paste your build into the patch checker and it walks that chain for you.

What it is

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

Sources

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N