Impact
The vulnerability arises when an attacker can externally control a file name or path used by a .NET component. By supplying a malicious path, an unauthorized user can elevate their privileges over the network, potentially gaining higher access rights or executing code with elevated permissions. This flaw is rooted in improper validation of file paths (CWE-200, CWE-522, CWE-73).
Affected Systems
Affected products include Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2026 version 18.9, and Microsoft Diagnostics Runtime. All identified versions are impacted; patching to the latest released versions is recommended.
Risk and Exploitability
The CVSS score of 7.5 indicates a high potential impact if exploited. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog, so current exploitation probability is unknown. The likely attack vector is remote over a network, where an attacker supplies a crafted file name or path to elevate privileges, as inferred from the description. Early remediation is advised to mitigate potential privilege escalation.
OpenCVE Enrichment