CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-rg75-q538-x34v: Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability

highCVSS 7.5CVE-2026-32175
Executive Summary: Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files. Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/396 CVSS Details - Version: 3.1 - Severity: - Score: 4.3 - Vector: /AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N - Weakness: CWE-36: Absolute Path Traversal Affected Platforms - Platforms: Windows - Architectures: All <a name="affected-packages"></a>Affected Packages The vulnerability affects any Microsoft .NET project if it uses any of affected package versions listed below <a name=".NET 10"></a>.NET 10 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.NetCore.App.Runtime.win-arm | >= 10.0.0, <= 10.0.7 | 10.0.8 Microsoft.NetCore.App.Runtime.win-arm64 | >= 10.0.0, <= 10.0.7 | 10.0.8 Microsoft.NetCore.App.Runtime.win-x64 | >= 10.0.0, <= 10.0.7 | 10.0.8 Microsoft.NetCore.App.Runtime.win-x86 | >= 10.0.0, <= 10.0.7 | 10.0.8 <a name=".NET 9"></a>.NET 9 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.NetCore.App.Runtime.win-arm | >= 9.0.0, <= 9.0.15 | 9.0.16 Microsoft.NetCore.App.Runtime.win-arm64 | >= 9.0.0, <= 9.0.15 | 9.0.16 Microsoft.NetCo

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high — CVSS 7.5
Published
2026-05-18
Last updated
2026-07-15
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-rg75-q538-x34v

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-32175coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from GitHub Security Advisories