Impact
This vulnerability stems from improper removal of sensitive information before it is stored or transmitted within the .NET framework. An attacker who can access the network may read data that should have been sanitized, potentially compromising confidential information.
Affected Systems
Microsoft .NET Frameworks version 8.0, 9.0, and 10.0, as well as Microsoft Visual Studio 2022 (version 17.14) and Visual Studio 2026 (version 18.8) are affected.
Risk and Exploitability
The CVSS score of 5.9 marks it as moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over the network, where an attacker can obtain sensitive data exposed because of the missing removal step.
OpenCVE Enrichment