Buffer Over-read Vulnerability in Microsoft ASP.NET Products
CVE-2025-36855

8.8HIGH

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
8 September 2025

What is CVE-2025-36855?

A buffer over-read vulnerability exists in DiaSymReader.dll, where the product reads from a buffer incorrectly, allowing access to memory locations beyond the intended limit. This affects specific End Of Life (EOL) versions of ASP.NET, including 6.0.0 up to 6.0.36, as well as 8.0.0 up to 8.0.11 and 9.0.0 up to 9.0.0. Any self-contained applications targeting these versions will also be vulnerable and require recompilation and redeployment. Microsoft has confirmed that no future updates or support will be provided for these EOL components, urging immediate action for those still utilizing them.

Affected Version(s)

.NET 6.0 Unknown 6.0.0 < 6.0.36

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36855 : Buffer Over-read Vulnerability in Microsoft ASP.NET Products