Impact
The flaw is an improper encoding or escaping of output in Microsoft .NET identified as CWE-116. An attacker with authorized access can cause the application to send falsified data over a network, leading to spoofing of traffic or identities. The vulnerability does not provide remote code execution or denial of service, but it allows an upstream system or user to believe that they are receiving legitimate data from a trusted source.
Affected Systems
All listed Microsoft products are affected: .NET 10.0, 8.0, and 9.0, .NET Framework 3.5, the combinations of .NET Framework 3.5 with 4.7.2, 4.8 and 4.8.1, .NET Framework 4.6.2 through 4.7.2, .NET Framework 4.8, Microsoft Visual Studio 2022 versions 17.12 and 17.14, and Microsoft Visual Studio 2026 version 18.7. No specific sub‑versions are given; the advisory covers the releases mentioned.
Risk and Exploitability
The CVSS score of 6.5 categorises the issue as moderate severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not present in the CISA KEV catalogue, further suggesting limited current exploitation. An authorised attacker who can influence application behaviour is needed. The defect allows network spoofing rather than remote execution, so the attack surface is constrained to environments where the attacker can inject crafted requests or responses through the affected .NET runtime.
OpenCVE Enrichment
Github GHSA
Ubuntu USN