CVE-2025-21176
Vulnerability Summary
Timeline
Description
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
CVSS Metrics
- v3.1•HIGH•Score: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- v3.1•HIGH•Score: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 1.41%• Percentile: 81%
Techniques & Countermeasures
- CWE-126•Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Affected Systems
- microsoft•microsoft .net framework 3.5 and 4.6.2/4.7/4.7.1/4.7.2
≥ 3.0.0.0, < 10.0.14393.7699
- microsoft•microsoft .net framework 3.5 and 4.7.2
≥ 4.7.0, < 4.7.04126.01
- microsoft•microsoft .net framework 3.5 and 4.8
≥ 4.8.0, < 4.8.04775.01
- microsoft•microsoft .net framework 3.5 and 4.8.1
≥ 4.8.1, < 4.8.1.09294.01
- microsoft•microsoft .net framework 4.6.2
≥ 4.7.0, < 4.7.04126.01
- microsoft•microsoft .net framework 4.6.2/4.7/4.7.1/4.7.2
≥ 4.7.0, < 4.7.04126.01
- microsoft•microsoft .net framework 4.6/4.6.2
≥ 10.0.0.0, < 10.0.10240.20890
- microsoft•microsoft .net framework 4.8
≥ 4.8.0, < 4.8.04775.01
- microsoft•microsoft visual studio 2015 update 3
≥ 14.0.0, < 14.0.24252.2
- microsoft•microsoft visual studio 2017 version 15.9 (includes 15.0 - 15.8)
≥ 15.9.0, < 15.9.69
- microsoft•microsoft visual studio 2019 version 16.11 (includes 16.0 - 16.10)
≥ 16.11.0, < 16.11.43
- microsoft•microsoft visual studio 2022 version 17.10
≥ 17.10, < 17.10.10 | ≥ 17.10.0, < 17.10.10
- microsoft•microsoft visual studio 2022 version 17.12
≥ 17.0, < 17.12.4 | ≥ 17.12.0, < 17.12.4
- microsoft•microsoft visual studio 2022 version 17.6
≥ 17.6.0, < 17.6.22
- microsoft•microsoft visual studio 2022 version 17.8
≥ 17.8.0, < 17.8.17
- microsoft•.net
8.0.0 | 9.0.0
- microsoft•.net 8.0
≥ 8.0.0, < 8.0.12
- microsoft•.net 9.0
≥ 9.0.0, < 9.0.1
- Unknown•.NET Framework
4.6 | 4.6.2 | 3.5 | 4.8.1 | 4.7 | 4.7.1 | 4.7.2 | 4.8
- microsoft•visual_studio_2017
≥ 15.0, < 15.9.69
- NuGet•Microsoft.NetCore.App.Runtime.linux-arm
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.0.12
- NuGet•Microsoft.NetCore.App.Runtime.linux-arm64
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.0.12
- NuGet•Microsoft.NetCore.App.Runtime.linux-musl-arm
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.0.12
- NuGet•Microsoft.NetCore.App.Runtime.linux-musl-arm64
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.0.12
- NuGet•Microsoft.NetCore.App.Runtime.linux-musl-x64
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.0.12
- NuGet•Microsoft.NetCore.App.Runtime.linux-x64
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.0.12
- NuGet•Microsoft.NetCore.App.Runtime.osx-arm64
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.0.12
- NuGet•Microsoft.NetCore.App.Runtime.osx-x64
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.0.12
- NuGet•Microsoft.NetCore.App.Runtime.win-arm
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.0.12
- NuGet•Microsoft.NetCore.App.Runtime.win-arm64
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.0.12
- NuGet•Microsoft.NetCore.App.Runtime.win-x64
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.0.12
- NuGet•Microsoft.NetCore.App.Runtime.win-x86
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.0.12