7.5
CVE-2026-32178
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:31
- Zuletzt bearbeitet 07.05.2026 19:41:12
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
.NET Spoofing Vulnerability
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Visual Studio 2022 Version >= 17.12.0 < 17.12.19
Microsoft ≫ Visual Studio 2022 Version >= 17.14.0 < 17.14.30
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.154 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-138 Improper Neutralization of Special Elements
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as control elements or syntactic markers when they are sent to a downstream component.