Heap and Integer Overflow Vulnerability in Microsoft Development Tools
CVE-2025-36853
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 8 September 2025
What is CVE-2025-36853?
A vulnerability exists in the msdia140.dll component associated with Microsoft's development tools, arising from an integer overflow and heap-based buffer overflow. This condition occurs when a calculation results in a value exceeding the permissible range, leading to potential overwriting of critical memory allocated on the heap. As a result, an attacker could exploit this flaw to execute arbitrary code on affected systems. Microsoft has confirmed that this vulnerability impacts End Of Life (EOL) software components, and they will not issue any future patches or support.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
.NET 6.0 Windows 6.0.0 < 6.0.36
Microsoft.NetCore.App.Runtime.linux-arm Windows >=6.0.0 <= 6.0.36
Microsoft.NetCore.App.Runtime.linux-arm64 Windows >=6.0.0 <= 6.0.36
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved