CVE-2025-21172
published 2025-01-14CVE-2025-21172: .NET and Visual Studio Remote Code Execution Vulnerability
PriorityP347high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
1.79%
76.0th percentile
.NET and Visual Studio Remote Code Execution Vulnerability
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >=6.0.0 – 6.0.36 | — |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >=6.0.0 – 6.0.36 | — |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >=6.0.0 – 6.0.36 | — |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >=6.0.0 – 6.0.36 | — |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >=6.0.0 – 6.0.36 | — |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >=6.0.0 – 6.0.36 | — |
| microsoft | microsoft.netcore.app.runtime.osx-arm64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.osx-arm64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.osx-arm64 | >=6.0.0 – 6.0.36 | — |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >=6.0.0 – 6.0.36 | — |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 8.0.0 < 8.0.12 | 8.0.12 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2025-01-16·CVSS 7.5
CVE-2025-21176 [HIGH] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET.
It was discovered that .NET did not properly handle input provided to its
Convert.TryToHexString method. An attacker could possibly use this issue
to execute arbitrary code. (CVE-2025-21171)
It was discovered that .NET did not properly handle an integer overflow
when processing certain specially crafted files. An attacker could
possibly use this issue to execute arbitrary code. (CVE-2025-21172)
Daniel Plaisted and Noah Gilson discovered that .NET insecurely handled
temporary file usage which could result in malicious package dependency
injection. An attacker could possibly use this issue to elevate privileges.
(CVE-2025-21173)
It was discovered that .NET did not properly perform input data validation
when
Microsoft
.NET and Visual Studio Remote Code Execution Vulnerability
vendor_msrc·2025-01-14·CVSS 7.5
CVE-2025-21172 [HIGH] CWE-190 .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
Exploitation of this vulnerability requires that an attacker convinces a user to open a maliciously crafted package file in Visual Studio.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment of the targeted component.
.NET and Visual Studio: .NET and Visual Studio
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Le
Red Hat
dotnet: .NET and Visual Studio Remote Code Execution Vulnerability
vendor_redhat·2025-01-14·CVSS 7.5
CVE-2025-21172 [HIGH] CWE-641 dotnet: .NET and Visual Studio Remote Code Execution Vulnerability
dotnet: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
A remote code execution vulnerability was found in .NET. This flaw allows an attacker to load a specially crafted file in .NET.
Statement: This issue affects .NET Framework as shipped with all versions of RHEL. However, this flaw is not known to be exploitable under any supported scenario.
```
.NET 6.0 for RHEL-8, RHEL-9 and RHIVOS has reached its End of Life as of November 12, 2024, and is no longer supported. No fixes will be provided for this stream. For additional information about lifecycle for .NET on Red Hat Enterprise Linux, please refer to: https://access.redhat.com/support/policy/updates/net-core.
```
Mitigation: Red Hat has investigated whether a poss
GHSA
GHSA-hg2w-qc44-hjcw: A vulnerability (CVE-2025-21172) exists in msdia140
ghsa_unreviewed·2025-09-08·CVSS 7.5
CVE-2025-36853 [HIGH] CWE-122 GHSA-hg2w-qc44-hjcw: A vulnerability (CVE-2025-21172) exists in msdia140
A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow.
Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Per CWE-190: Integer Overflow or Wraparound, is when a product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
NOTE: This
OSV
dotnet8, dotnet9 vulnerabilities
osv·2025-01-16·CVSS 7.5
CVE-2025-21171 [HIGH] dotnet8, dotnet9 vulnerabilities
dotnet8, dotnet9 vulnerabilities
It was discovered that .NET did not properly handle input provided to its
Convert.TryToHexString method. An attacker could possibly use this issue
to execute arbitrary code. (CVE-2025-21171)
It was discovered that .NET did not properly handle an integer overflow
when processing certain specially crafted files. An attacker could
possibly use this issue to execute arbitrary code. (CVE-2025-21172)
Daniel Plaisted and Noah Gilson discovered that .NET insecurely handled
temporary file usage which could result in malicious package dependency
injection. An attacker could possibly use this issue to elevate privileges.
(CVE-2025-21173)
It was discovered that .NET did not properly perform input data validation
when processing certain specially crafted files. An a
OSV
CVE-2025-21172
osv·2025-01-15·CVSS 7.5
CVE-2025-21172 [HIGH] CVE-2025-21172
.NET and Visual Studio Remote Code Execution Vulnerability
GHSA
Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
ghsa·2025-01-14·CVSS 7.5
CVE-2025-21172 [HIGH] CWE-122 Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
# Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An attacker could exploit this vulnerability by loading a specially crafted file in Visual Studio.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/runtime/issues/111424.
## Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
## Affected sof
OSV
Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
osv·2025-01-14·CVSS 7.5
CVE-2025-21172 [HIGH] Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
# Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An attacker could exploit this vulnerability by loading a specially crafted file in Visual Studio.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/runtime/issues/111424.
## Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
## Affected sof
No detection rules found.
No public exploits indexed.
2025-01-14
Published