Impact
This vulnerability stems from inclusion of code originating in an untrusted control sphere within the .NET framework, enabling an unauthorized attacker to read sensitive information across a network. The affected software exposes data that should remain internal, leading to potential breach of confidentiality. No higher‑level exploitation such as code execution is reported, but the exposure of domain or application data can aid further attacks. This issue represents CWE‑693, CWE‑829, and CWE‑918 weaknesses.
Affected Systems
Microsoft .NET 10.0, Microsoft .NET 8.0, Microsoft .NET 9.0, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2026 version 18.8 are impacted; specific version separators are not provided.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to target the affected runtime or development tools over a network; the exact method is inferred from the description about an information disclosure over a network, but no precise exploit vector is detailed in the data.
OpenCVE Enrichment
Github GHSA