Buffer Over-read Vulnerability in Microsoft ASP.NET Products
CVE-2025-36855
8.8HIGH
What is CVE-2025-36855?
A buffer over-read vulnerability exists in DiaSymReader.dll, where the product reads from a buffer incorrectly, allowing access to memory locations beyond the intended limit. This affects specific End Of Life (EOL) versions of ASP.NET, including 6.0.0 up to 6.0.36, as well as 8.0.0 up to 8.0.11 and 9.0.0 up to 9.0.0. Any self-contained applications targeting these versions will also be vulnerable and require recompilation and redeployment. Microsoft has confirmed that no future updates or support will be provided for these EOL components, urging immediate action for those still utilizing them.
Affected Version(s)
.NET 6.0 Unknown 6.0.0 < 6.0.36