cbcvebase.
CVE-2025-55248
published 2025-10-14

CVE-2025-55248: Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

PriorityP432medium5.7CVSS 3.1
AVNACLPRLUIRSUCHINAN
EPSS
0.67%
48.2th percentile
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

Affected

68 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft.netcore.app.runtime.linux-arm>= 8.0.0 < 8.0.218.0.21
microsoftmicrosoft.netcore.app.runtime.linux-arm>= 9.0.0 < 9.0.109.0.10
microsoftmicrosoft.netcore.app.runtime.linux-arm64>= 8.0.0 < 8.0.218.0.21
microsoftmicrosoft.netcore.app.runtime.linux-arm64>= 9.0.0 < 9.0.109.0.10
microsoftmicrosoft.netcore.app.runtime.linux-musl-arm>= 8.0.0 < 8.0.218.0.21
microsoftmicrosoft.netcore.app.runtime.linux-musl-arm>= 9.0.0 < 9.0.109.0.10
microsoftmicrosoft.netcore.app.runtime.linux-musl-arm64>= 8.0.0 < 8.0.218.0.21
microsoftmicrosoft.netcore.app.runtime.linux-musl-arm64>= 9.0.0 < 9.0.109.0.10
microsoftmicrosoft.netcore.app.runtime.linux-musl-x64>= 8.0.0 < 8.0.218.0.21
microsoftmicrosoft.netcore.app.runtime.linux-musl-x64>= 9.0.0 < 9.0.109.0.10
microsoftmicrosoft.netcore.app.runtime.linux-x64>= 8.0.0 < 8.0.218.0.21
microsoftmicrosoft.netcore.app.runtime.linux-x64>= 9.0.0 < 9.0.109.0.10
microsoftmicrosoft.netcore.app.runtime.osx-arm64>= 8.0.0 < 8.0.218.0.21
microsoftmicrosoft.netcore.app.runtime.osx-arm64>= 9.0.0 < 9.0.109.0.10
microsoftmicrosoft.netcore.app.runtime.osx-x64>= 8.0.0 < 8.0.218.0.21
microsoftmicrosoft.netcore.app.runtime.osx-x64>= 9.0.0 < 9.0.109.0.10
microsoftmicrosoft.netcore.app.runtime.win-arm>= 8.0.0 < 8.0.218.0.21
microsoftmicrosoft.netcore.app.runtime.win-arm>= 9.0.0 < 9.0.109.0.10
microsoftmicrosoft.netcore.app.runtime.win-arm64>= 8.0.0 < 8.0.218.0.21
microsoftmicrosoft.netcore.app.runtime.win-arm64>= 9.0.0 < 9.0.109.0.10
microsoftmicrosoft.netcore.app.runtime.win-x64>= 8.0.0 < 8.0.218.0.21
microsoftmicrosoft.netcore.app.runtime.win-x64>= 9.0.0 < 9.0.109.0.10
microsoftmicrosoft.netcore.app.runtime.win-x86>= 8.0.0 < 8.0.218.0.21
microsoftmicrosoft.netcore.app.runtime.win-x86>= 9.0.0 < 9.0.109.0.10
microsoftmicrosoft_net_framework_2.0_service_pack_2>= 2.0.0 < 2.0.50727.89812.0.50727.8981

CVSS provenance

nvdv3.15.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
ghsa5.7MEDIUM
osv7.3HIGH
vendor_ubuntu7.3HIGH
vendor_msrc4.8MEDIUM
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.