CVE-2025-55247
published 2025-10-14CVE-2025-55247: Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
PriorityP343high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.56%
42.4th percentile
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | net | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | net_8.0 | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | net_9.0 | >= 9.0.0 < 9.0.10 | 9.0.10 |
| msrc | net_8.0_installed_on_linux | — | — |
| msrc | net_9.0_installed_on_linux | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
ghsa7.3HIGH
osv7.3HIGH
vendor_msrc7.3HIGH
vendor_redhat7.3HIGH
vendor_ubuntu7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
dotnet8, dotnet9, dotnet10 vulnerabilities
osv·2025-10-16·CVSS 7.3
CVE-2025-55247 [HIGH] dotnet8, dotnet9, dotnet10 vulnerabilities
dotnet8, dotnet9, dotnet10 vulnerabilities
It was discovered that .NET did not properly handle the creation of temporary
build time directories. An attacker could possibly use this issue to cause a
denial of service. (CVE-2025-55247)
It was discovered that .NET did not properly establish TLS sessions for
SMTP server connections. An attacker could use this issue to cause .NET
to use unencrypted connections. This issue only affects .NET versions 8.0
and 9.0. (CVE-2025-55248)
It was discovered that .NET inconsistently interpreted certain http
requests. An attacker could possibly use this to bypass a security feature
over a network. (CVE-2025-55315)
OSV
Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
osv·2025-10-15·CVSS 7.3
CVE-2025-55247 [HIGH] Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0.xxx, .NET 9.0.xxx and .NET 10.0.xxx. This advisory also provides guidance on what developers can do to update their environments to remove this vulnerability.
A vulnerability exists in .NET where predictable paths for MSBuild's temporary directories on Linux let another user create the directories ahead of MSBuild, leading to DoS of builds. This only affects .NET on Linux operating systems.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/370
GHSA
Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
ghsa·2025-10-15·CVSS 7.3
CVE-2025-55247 [HIGH] CWE-59 Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0.xxx, .NET 9.0.xxx and .NET 10.0.xxx. This advisory also provides guidance on what developers can do to update their environments to remove this vulnerability.
A vulnerability exists in .NET where predictable paths for MSBuild's temporary directories on Linux let another user create the directories ahead of MSBuild, leading to DoS of builds. This only affects .NET on Linux operating systems.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/370
GHSA
Duplicate Advisory: Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
ghsa·2025-10-14·CVSS 7.3
CVE-2025-55247 [HIGH] CWE-59 Duplicate Advisory: Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
Duplicate Advisory: Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-w3q9-fxm7-j8fq. This link is maintained to preserve external references.
### Original Description
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
OSV
Duplicate Advisory: Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
osv·2025-10-14·CVSS 7.3
CVE-2025-55247 [HIGH] Duplicate Advisory: Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
Duplicate Advisory: Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-w3q9-fxm7-j8fq. This link is maintained to preserve external references.
### Original Description
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
OSV
CVE-2025-55247: Improper link resolution before file access ('link following') in
osv·2025-10-14·CVSS 7.3
CVE-2025-55247 [HIGH] CVE-2025-55247: Improper link resolution before file access ('link following') in
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2025-10-16·CVSS 7.3
CVE-2025-55248 [HIGH] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET
It was discovered that .NET did not properly handle the creation of temporary
build time directories. An attacker could possibly use this issue to cause a
denial of service. (CVE-2025-55247)
It was discovered that .NET did not properly establish TLS sessions for
SMTP server connections. An attacker could use this issue to cause .NET
to use unencrypted connections. This issue only affects .NET versions 8.0
and 9.0. (CVE-2025-55248)
It was discovered that .NET inconsistently interpreted certain http
requests. An attacker could possibly use this to bypass a security feature
over a network. (CVE-2025-55315)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dotnet: .NET Denial of Service Vulnerability
vendor_redhat·2025-10-15·CVSS 7.3
CVE-2025-55247 [HIGH] CWE-377 dotnet: .NET Denial of Service Vulnerability
dotnet: .NET Denial of Service Vulnerability
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
A flaw was found in MSBuild’s temporary directory handling on Linux where predictable, non-randomized temporary paths are used. Local users can create or manipulate those paths before MSBuild runs, causing build failures or unexpected behavior and resulting in denial of service for build operations.
Statement: The Red Hat Product Security team has assessed this issue as Moderate. Predictable MSBuild temporary directory paths on Linux allow a local user to precreate or manipulate build temp directories, causing build failures (denial of service) on shared build hosts or CI runners using the affected .NET packages.
Microsoft
.NET Elevation of Privilege Vulnerability
vendor_msrc·2025-10-14·CVSS 7.3
CVE-2025-55247 [HIGH] CWE-59 .NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
Description: Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain the privileges of the authenticated user.
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability?
An authenticated attacker could place a malicious file in the core project path and then wait for a user with admin privileges to create or build a .NET project to gain elevated privileges.
.NET: .NET
Microsoft: Microsoft
Customer Action Requir
No detection rules found.
No public exploits indexed.
Qualys
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review | Qualys
blogs_qualys·2025-10-14
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for October 2025
- Adobe Patches for October 2025
- Zero-day Vulnerabilities Patched in October Patch Tuesday Edition
- Critical Severity Vulnerabilities Patched in October Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response with TruRisk Eliminate
- Automating Risk Elimination and Accelerating Response: Meet Agent Sara
- EVALUATE Vendor-Suggested Mitigation withPolicy Audit
- Qualys Monthly Webinar Series
As cybersecurity threats evolve, Microsoft’s October 2025 Patch Tuesday delivers one of the most comprehensive security updates of the year. Here’s a quick breakdown of what you need t
Qualys
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review
blogs_qualys·2025-10-14
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for October 2025
Adobe Patches for October 2025
Zero-day Vulnerabilities Patched in October Patch Tuesday Edition
Critical Severity Vulnerabilities Patched in October Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response with TruRisk Eliminate
Automating Risk Elimination and Accelerating Response: Meet Agent Sara
EVALUATE Vendor-Suggested Mitigation withPolicy Audit
Qualys Monthly Webinar Series
As cybersecurity threats evolve, Microsoft’s October 2025 Patch Tuesday delivers one of the most comprehensive security updates of the year. Here’s a quick breakdown of what you need to know.
## Mi
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
blogs_bleepingcomputer·2025-10-14·CVSS 7.8
[HIGH] Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
## Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
## Lawrence Abrams
80 Elevation of Privilege Vulnerabilities
11 Security Feature Bypass Vulnerabilities
31 Remote Code Execution Vulnerabilities
28 Information Disclosure Vulnerabilities
11 Denial of Service Vulnerabilities
10 Spoofing Vulnerabilities
When BleepingComputer reports on the Patch Tuesday security updates, we only count those released today by Microsoft. Therefore, the number of flaws does not include those fixed in Azure, Mariner, Microsoft Edge, and other vulnerabilities earlier this month.
Notably, Windows 10 reaches the end of support today , with this being the last Patch Tuesday where Microsoft provides free security updates to the venerable operating system.
To continue receiving security upd
Bugzilla
CVE-2025-55247 dotnet: .NET Denial of Service Vulnerability
bugzilla·2025-10-10·CVSS 7.3
CVE-2025-55247 [HIGH] CVE-2025-55247 dotnet: .NET Denial of Service Vulnerability
CVE-2025-55247 dotnet: .NET Denial of Service Vulnerability
A vulnerability exists in .NET Core where predictable paths for
MSBuild's temporary directories on Linux let another user create the
directories ahead of MSBuild, leading to DoS of builds.
Affected versions:
.NET 8.0 (that's the RHEL dotnet8.0 package)
.NET 9.0 (that's the RHEL dotnet9.0 package)
.NET 10.0 (that's the RHEL dotnet10.0 package)
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:18148 https://access.redhat.com/errata/RHSA-2025:18148
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:18149 https://access.redhat.com/errata/RHSA-2025:18149
---
This issue has been addressed in the following products:
2025-10-14
Published