.NET Framework Remote Code Execution Vulnerability Affecting Microsoft Products
CVE-2025-21176

8.8HIGH

Summary

This vulnerability in the .NET Framework and Visual Studio allows an attacker to execute arbitrary code on the affected systems. By exploiting this flaw, unauthorized remote entities can potentially gain access to sensitive data and control over applications, leading to severe consequences for users and organizations. Users of affected products should apply available updates promptly to mitigate the risk.

Affected Version(s)

.NET 8.0 Unknown 8.0.0 < 8.0.12

.NET 9.0 Unknown 9.0.0 < 9.0.1

Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Windows 10 Version 1607 for 32-bit Systems 3.0.0.0 < 10.0.14393.7699

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.