CVE-2025-55248
published 2025-10-14CVE-2025-55248: Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
PriorityP432medium5.7CVSS 3.1
AVNACLPRLUIRSUCHINAN
EPSS
0.67%
48.2th percentile
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | microsoft.netcore.app.runtime.osx-arm64 | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | microsoft.netcore.app.runtime.osx-arm64 | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 8.0.0 < 8.0.21 | 8.0.21 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 9.0.0 < 9.0.10 | 9.0.10 |
| microsoft | microsoft_net_framework_2.0_service_pack_2 | >= 2.0.0 < 2.0.50727.8981 | 2.0.50727.8981 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
ghsa5.7MEDIUM
osv7.3HIGH
vendor_ubuntu7.3HIGH
vendor_msrc4.8MEDIUM
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
dotnet8, dotnet9, dotnet10 vulnerabilities
osv·2025-10-16·CVSS 7.3
CVE-2025-55247 [HIGH] dotnet8, dotnet9, dotnet10 vulnerabilities
dotnet8, dotnet9, dotnet10 vulnerabilities
It was discovered that .NET did not properly handle the creation of temporary
build time directories. An attacker could possibly use this issue to cause a
denial of service. (CVE-2025-55247)
It was discovered that .NET did not properly establish TLS sessions for
SMTP server connections. An attacker could use this issue to cause .NET
to use unencrypted connections. This issue only affects .NET versions 8.0
and 9.0. (CVE-2025-55248)
It was discovered that .NET inconsistently interpreted certain http
requests. An attacker could possibly use this to bypass a security feature
over a network. (CVE-2025-55315)
GHSA
Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
ghsa·2025-10-15·CVSS 5.7
CVE-2025-55248 [MEDIUM] CWE-326 Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
# Microsoft Security Advisory CVE-2025-55248 | .NET Information Disclosure Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A MITM (man in the middle) attacker may prevent use of TLS between client and SMTP server, forcing client to send data over unencrypted connection.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/372
## Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
OSV
Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
osv·2025-10-15·CVSS 5.7
CVE-2025-55248 [MEDIUM] Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
# Microsoft Security Advisory CVE-2025-55248 | .NET Information Disclosure Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A MITM (man in the middle) attacker may prevent use of TLS between client and SMTP server, forcing client to send data over unencrypted connection.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/372
## Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
OSV
CVE-2025-55248: Inadequate encryption strength in
osv·2025-10-14·CVSS 5.7
CVE-2025-55248 [MEDIUM] CVE-2025-55248: Inadequate encryption strength in
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
GHSA
Duplicate Advisory: Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
ghsa·2025-10-14·CVSS 5.7
CVE-2025-55248 [MEDIUM] CWE-326 Duplicate Advisory: Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
Duplicate Advisory: Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-gwq6-fmvp-qp68. This link is maintained to preserve external references.
### Original Description
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
OSV
Duplicate Advisory: Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
osv·2025-10-14·CVSS 5.7
CVE-2025-55248 [MEDIUM] Duplicate Advisory: Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
Duplicate Advisory: Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-gwq6-fmvp-qp68. This link is maintained to preserve external references.
### Original Description
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2025-10-16·CVSS 7.3
CVE-2025-55248 [HIGH] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET
It was discovered that .NET did not properly handle the creation of temporary
build time directories. An attacker could possibly use this issue to cause a
denial of service. (CVE-2025-55247)
It was discovered that .NET did not properly establish TLS sessions for
SMTP server connections. An attacker could use this issue to cause .NET
to use unencrypted connections. This issue only affects .NET versions 8.0
and 9.0. (CVE-2025-55248)
It was discovered that .NET inconsistently interpreted certain http
requests. An attacker could possibly use this to bypass a security feature
over a network. (CVE-2025-55315)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dotnet: .NET Information Disclosure Vulnerability
vendor_redhat·2025-10-15·CVSS 4.8
CVE-2025-55248 [MEDIUM] CWE-319 dotnet: .NET Information Disclosure Vulnerability
dotnet: .NET Information Disclosure Vulnerability
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
A flaw exists in certain .NET builds where a man-in-the-middle (MITM) attacker can prevent or downgrade TLS between a client and an SMTP server. This may cause the client to send credentials or message data over an unencrypted connection, exposing sensitive information to the attacker.
Statement: The Red Hat Product Security team has assessed the severity of this vulnerability as High, given that it can be remotely exploited by a man-in-the-middle attacker without authentication or user interaction. Successful exploitation allows an attacker to disable TLS protection between a .NET client and an SMTP
Microsoft
.NET, .NET Framework, and Visual Studio Information Disclosure Vulnerability
vendor_msrc·2025-10-14·CVSS 4.8
CVE-2025-55248 [MEDIUM] CWE-326 .NET, .NET Framework, and Visual Studio Information Disclosure Vulnerability
.NET, .NET Framework, and Visual Studio Information Disclosure Vulnerability
Description: Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is Personally Identifiable Information (PII).
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability?
An authorized attacker with read/write privileges must send a victim a malicious email, or share the link to a malicious email, and convince them to open it.
.NET, .NET Framework, Visual St
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-55248 dotnet: .NET Information Disclosure Vulnerability
bugzilla·2025-10-10·CVSS 5.7
CVE-2025-55248 [MEDIUM] CVE-2025-55248 dotnet: .NET Information Disclosure Vulnerability
CVE-2025-55248 dotnet: .NET Information Disclosure Vulnerability
MITM (man in the middle) attacker may prevent use of TLS between client
and SMTP server, forcing client to send data over unencrypted
connection.
Affected versions:
.NET 8.0 (that's the RHEL dotnet8.0 package)
.NET 9.0 (that's the RHEL dotnet9.0 package)
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:18148 https://access.redhat.com/errata/RHSA-2025:18148
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:18149 https://access.redhat.com/errata/RHSA-2025:18149
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:18152 https://access.redhat.com/errata/RH
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
blogs_bleepingcomputer·2025-10-14·CVSS 7.8
[HIGH] Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
## Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
## Lawrence Abrams
80 Elevation of Privilege Vulnerabilities
11 Security Feature Bypass Vulnerabilities
31 Remote Code Execution Vulnerabilities
28 Information Disclosure Vulnerabilities
11 Denial of Service Vulnerabilities
10 Spoofing Vulnerabilities
When BleepingComputer reports on the Patch Tuesday security updates, we only count those released today by Microsoft. Therefore, the number of flaws does not include those fixed in Azure, Mariner, Microsoft Edge, and other vulnerabilities earlier this month.
Notably, Windows 10 reaches the end of support today , with this being the last Patch Tuesday where Microsoft provides free security updates to the venerable operating system.
To continue receiving security upd
Wiz
CVE-2026-21257 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.8
CVE-2026-21257 [MEDIUM] CVE-2026-21257 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21257 :
Visual Studio 2022 vulnerability analysis and mitigation
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network.
Source : NVD
## 8
Score
Published February 10, 2026
Severity HIGH
CNA Score 8.0
Affected Technologies
Visual Studio 2022
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:microsoft:visual_studio_2022
Sources
Windows Severity HIGH Has Fix Added at: Feb 11, 2026
Windows Severity HIGH Has Fix Added at: Feb 12, 2026
## Get a CVE risk assessme
Wiz
CVE-2026-21256 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.8
CVE-2026-21256 [MEDIUM] CVE-2026-21256 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21256 :
Visual Studio 2022 vulnerability analysis and mitigation
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.
Source : NVD
## 8.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Visual Studio 2022
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:microsoft:visual_studio_2022
Sources
Windows Severity HIGH Has Fix Added at: Feb 11, 2026
Windows Severity HIGH Has Fix Added at: Feb 12, 2026
## Get a CVE risk assessment
2025-10-14
Published