CVE-2025-21176
published 2025-01-14CVE-2025-21176: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.30%
81.4th percentile
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.osx-arm64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.osx-arm64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 8.0.0 < 8.0.12 | 8.0.12 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 9.0.0 < 9.0.1 | 9.0.1 |
| microsoft | net | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa8.8HIGH
osv8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2025-01-16·CVSS 7.5
CVE-2025-21176 [HIGH] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET.
It was discovered that .NET did not properly handle input provided to its
Convert.TryToHexString method. An attacker could possibly use this issue
to execute arbitrary code. (CVE-2025-21171)
It was discovered that .NET did not properly handle an integer overflow
when processing certain specially crafted files. An attacker could
possibly use this issue to execute arbitrary code. (CVE-2025-21172)
Daniel Plaisted and Noah Gilson discovered that .NET insecurely handled
temporary file usage which could result in malicious package dependency
injection. An attacker could possibly use this issue to elevate privileges.
(CVE-2025-21173)
It was discovered that .NET did not properly perform input data validation
when
Red Hat
dotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
vendor_redhat·2025-01-14·CVSS 8.8
CVE-2025-21176 [HIGH] CWE-126 dotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
dotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
A remote code execution vulnerability was found in .NET. This flaw allows an attacker to load a specially crafted file in .NET.
Statement: This issue affects .NET Framework as shipped with all versions of RHEL. However, this flaw is not known to be exploitable under any supported scenario.
```
.NET 6.0 for RHEL-8, RHEL-9 and RHIVOS has reached its End of Life as of November 12, 2024, and is no longer supported. No fixes will be provided for this stream. For additional information about lifecycle for .NET on Red Hat Enterprise Linux, please refer to: https://access.redhat.com/support/policy/updates/net-core.
```
Mitigation: Red H
Microsoft
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
vendor_msrc·2025-01-14·CVSS 8.8
CVE-2025-21176 [HIGH] CWE-126 .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
Exploitation of this vulnerability requires that an attacker convinces a user to open a maliciously crafted package file in Visual Studio.
.NET, .NET Framework, Visual Studio: .NET, .NET Framework, Visual Studio
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: http://aka.ms/vs/15/release/latest
Reference: https://docs.microsoft.com/en-us/visualstudio/releasenotes/vs2017-relnotes
Reference: https://my.visualstudio.com/Downloa
GHSA
GHSA-642h-ggvv-j2c4: A vulnerability ( CVE-2025-21176 https://www
ghsa_unreviewed·2025-09-08·CVSS 8.8
CVE-2025-36855 [HIGH] CWE-126 GHSA-642h-ggvv-j2c4: A vulnerability ( CVE-2025-21176 https://www
A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read.
Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
This issue affects EOL ASP.NET 6.0.0 <= 6.0.36 as represented in this CVE, as well as 8.0.0 <= 8.0.11 & <= 9.0.0 as represented in CVE-2025-21176.
Additionally, if you've deployed self-contained applications https://docs.microsoft.com/dotnet/core/deploying/#self-contained-deployments-scd targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed.
NOTE: This CVE af
OSV
dotnet8, dotnet9 vulnerabilities
osv·2025-01-16·CVSS 7.5
CVE-2025-21171 [HIGH] dotnet8, dotnet9 vulnerabilities
dotnet8, dotnet9 vulnerabilities
It was discovered that .NET did not properly handle input provided to its
Convert.TryToHexString method. An attacker could possibly use this issue
to execute arbitrary code. (CVE-2025-21171)
It was discovered that .NET did not properly handle an integer overflow
when processing certain specially crafted files. An attacker could
possibly use this issue to execute arbitrary code. (CVE-2025-21172)
Daniel Plaisted and Noah Gilson discovered that .NET insecurely handled
temporary file usage which could result in malicious package dependency
injection. An attacker could possibly use this issue to elevate privileges.
(CVE-2025-21173)
It was discovered that .NET did not properly perform input data validation
when processing certain specially crafted files. An a
OSV
CVE-2025-21176
osv·2025-01-15·CVSS 8.8
CVE-2025-21176 [HIGH] CVE-2025-21176
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
GHSA
Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
ghsa·2025-01-14·CVSS 8.8
CVE-2025-21176 [HIGH] CWE-126 Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
# Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An attacker could exploit this vulnerability by loading a specially crafted file in Visual Studio.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/runtime/issues/111425
## Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
## Affected soft
OSV
Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
osv·2025-01-14·CVSS 8.8
CVE-2025-21176 [HIGH] Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
# Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An attacker could exploit this vulnerability by loading a specially crafted file in Visual Studio.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/runtime/issues/111425
## Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
## Affected soft
No detection rules found.
No public exploits indexed.
2025-01-14
Published