Impact
Improper validation of a specified type of input in the Microsoft .NET Framework creates a denial of service condition that can be triggered by an attacker who sends crafted data over a network. The vulnerability is classified as CWE-1287. No privilege escalation or data compromise is required; the impact is loss of availability for any application running on the affected framework.
Affected Systems
Affected versions include Microsoft .NET 10.0, 9.0, and 8.0, as well as Microsoft Visual Studio 2022 releases 17.12 and 17.14 and Microsoft Visual Studio 2026 release 18.7. All listed products are susceptible to the described input validation flaw, which can disrupt service for applications built against those frameworks.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk, while an EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote network connection, where an adversary can transmit malicious input from outside the local environment to trigger the denial of service. No additional exploitation prerequisites are identified in the CVE data.
OpenCVE Enrichment
Github GHSA
Ubuntu USN