CVE-2019-0657: Microsoft .net Core

Medium severity, CVSS 5.9. EPSS: 4.5% chance of exploitation in the next 30 days.

A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.

Affected products

  • Microsoft .net Core: version 1.0 only; version 2.1 only; version 2.2 only
  • Microsoft .NET Framework: version 2.0 only; version 3.0 only; version 3.5 only; version 3.5.1 only; version 4.5.2 only; version 4.6 only; …
  • Microsoft PowerShell Core: version 6.0 only; version 6.1 only
  • Microsoft Visual Studio 2017: affected versions not specified; version 15.9 only

Published 2019-03-05. Last modified 2026-06-17.