CVE-2025-21171
published 2025-01-14CVE-2025-21171: .NET Remote Code Execution Vulnerability .NET Remote Code Execution Vulnerability
high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
1.67%
74.2th percentile
.NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.osx-arm64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft_visual_studio_2022_version_17.10 | >= 17.10.0 < 17.10.10 | 17.10.10 |
| microsoft | microsoft_visual_studio_2022_version_17.12 | >= 17.12.0 < 17.12.4 | 17.12.4 |
| microsoft | microsoft_visual_studio_2022_version_17.6 | >= 17.6.0 < 17.6.22 | 17.6.22 |
| microsoft | microsoft_visual_studio_2022_version_17.8 | >= 17.8.0 < 17.8.17 | 17.8.17 |
| microsoft | net_9.0 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | powershell_7.5 | >= 7.5.0 < 7.5.0 | 7.5.0 |
| msrc | microsoft_visual_studio_2022_version_17.10 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.12 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.6 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.8 | — | — |
| msrc | net_9.0_installed_on_linux | — | — |
| msrc | net_9.0_installed_on_mac_os | — | — |
| msrc | net_9.0_installed_on_windows | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
cvelistv57.5HIGH
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2025-01-16·CVSS 7.5
CVE-2025-21176 [HIGH] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET.
It was discovered that .NET did not properly handle input provided to its
Convert.TryToHexString method. An attacker could possibly use this issue
to execute arbitrary code. (CVE-2025-21171)
It was discovered that .NET did not properly handle an integer overflow
when processing certain specially crafted files. An attacker could
possibly use this issue to execute arbitrary code. (CVE-2025-21172)
Daniel Plaisted and Noah Gilson discovered that .NET insecurely handled
temporary file usage which could result in malicious package dependency
injection. An attacker could possibly use this issue to elevate privileges.
(CVE-2025-21173)
It was discovered that .NET did not properly perform input data validation
when
Red Hat
dotnet: .NET Remote Code Execution Vulnerability
vendor_redhat·2025-01-14·CVSS 7.5
CVE-2025-21171 [HIGH] CWE-122 dotnet: .NET Remote Code Execution Vulnerability
dotnet: .NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
A remote code execution vulnerability was found in .NET. This flaw allows an attacker to load a specially crafted file into a vulnerable application.
Statement: This issue affects .NET Framework version 9.0 as shipped with all versions of RHEL. However, this flaw is not known to be exploitable under any supported scenario.
```
.NET 6.0 for RHEL-8, RHEL-9 and RHIVOS has reached its End of Life as of November 12, 2024, and is no longer supported. For additional information about lifecycle for .NET on Red Hat Enterprise Linux, please refer to: https://access.redhat.com/support/policy/updates/net-core.
```
Mitigation: Red Hat has investigated whether a possible mitigation exists for this issue, and ha
Microsoft
.NET Remote Code Execution Vulnerability
vendor_msrc·2025-01-14·CVSS 7.5
CVE-2025-21171 [HIGH] CWE-122 .NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution?
This attack requires a victim to perform a specific action, such as copying files or executing a command, and for an attacker with appropriate access to have pre-planted malicious files with knowledge of where they should be placed on the victim's system.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
This attack requires a victim to perform a specific action, such as copying files or executing a command, and for an attacker with appropriate access to have pre-planted malicious files with knowledge of where t
OSV
dotnet8, dotnet9 vulnerabilities
osv·2025-01-16·CVSS 7.5
CVE-2025-21171 [HIGH] dotnet8, dotnet9 vulnerabilities
dotnet8, dotnet9 vulnerabilities
It was discovered that .NET did not properly handle input provided to its
Convert.TryToHexString method. An attacker could possibly use this issue
to execute arbitrary code. (CVE-2025-21171)
It was discovered that .NET did not properly handle an integer overflow
when processing certain specially crafted files. An attacker could
possibly use this issue to execute arbitrary code. (CVE-2025-21172)
Daniel Plaisted and Noah Gilson discovered that .NET insecurely handled
temporary file usage which could result in malicious package dependency
injection. An attacker could possibly use this issue to elevate privileges.
(CVE-2025-21173)
It was discovered that .NET did not properly perform input data validation
when processing certain specially crafted files. An a
OSV
Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
osv·2025-01-14·CVSS 7.5
CVE-2025-21171 [HIGH] Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
# Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An attacker could exploit this vulnerability by sending a specially crafted request to the vulnerable web server.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/runtime/issues/111423
## Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
## Affected software
* Any .NET 9.0 application r
GHSA
Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
ghsa·2025-01-14·CVSS 7.5
CVE-2025-21171 [HIGH] CWE-122 Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
# Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An attacker could exploit this vulnerability by sending a specially crafted request to the vulnerable web server.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/runtime/issues/111423
## Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
## Affected software
* Any .NET 9.0 application r
CVEList
.NET Remote Code Execution Vulnerability
cvelistv5·2025-01-14·CVSS 7.5
CVE-2025-21171 [HIGH] CWE-122 .NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws
blogs_bleepingcomputer·2025-01-14·CVSS 7.8
[HIGH] Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws
## Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws
## Lawrence Abrams
40 Elevation of Privilege Vulnerabilities
14 Security Feature Bypass Vulnerabilities
58 Remote Code Execution Vulnerabilities
24 Information Disclosure Vulnerabilities
20 Denial of Service Vulnerabilities
5 Spoofing Vulnerabilities
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5050009 & KB5050021 cumulative updates and the Windows 10 KB5048652 cumulative update.
## Three actively exploited zero-day disclosed
This month's Patch Tuesday fixes three actively exploited and five publicly exposed zero-day vulnerabilities.
Microsoft classifies a zero-day flaw as one that is publicly disclosed or actively exploited while no offi
Bugzilla
CVE-2025-21171 dotnet: .NET Remote Code Execution Vulnerability
bugzilla·2025-01-14·CVSS 7.5
CVE-2025-21171 [HIGH] CVE-2025-21171 dotnet: .NET Remote Code Execution Vulnerability
CVE-2025-21171 dotnet: .NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:0382 https://access.redhat.com/errata/RHSA-2025:0382
2025-01-14
Published