Microsoft Net Framework 3.5 And 4.8 vulnerabilities

36 known vulnerabilities affecting microsoft/microsoft_net_framework_3.5_and_4.8.

Total CVEs
36
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH29MEDIUM5

Vulnerabilities

Page 1 of 2
CVE-2026-23666HIGHCVSS 7.5≥ 4.8.0, < 2.0.50727.9068 & 3.0.30729.9065 & 4.8.4801.02026-04-14
CVE-2026-23666 [HIGH] CWE-755 CVE-2026-23666: Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-33116HIGHCVSS 7.5≥ 4.8.0, < 2.0.50727.9068 & 3.0.30729.9065 & 4.8.4801.02026-04-14
CVE-2026-33116 [HIGH] CWE-20 CVE-2026-33116: Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-32226MEDIUMCVSS 5.9≥ 4.8.0, < 2.0.50727.9068 & 3.0.30729.9065 & 4.8.4801.02026-04-14
CVE-2026-32226 [MEDIUM] CWE-362 CVE-2026-32226: Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2025-55248MEDIUMCVSS 5.7≥ 4.8.0, < 4.8.04798.022025-10-14
CVE-2025-55248 [MEDIUM] CWE-326 CVE-2025-55248: Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
cvelistv5nvd
CVE-2025-21176HIGHCVSS 8.8≥ 4.8.0, < 4.8.04775.012025-01-14
CVE-2025-21176 [HIGH] CWE-126 .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2024-43484HIGHCVSS 7.5≥ 4.8.0, < 4.8.04762.012024-10-08
CVE-2024-43484 [HIGH] CWE-407 CVE-2024-43484: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
cvelistv5nvd
CVE-2024-43483HIGHCVSS 7.5≥ 4.8.0, < 4.8.04762.012024-10-08
CVE-2024-43483 [HIGH] CWE-407 CVE-2024-43483: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
cvelistv5nvd
CVE-2024-38081HIGHCVSS 7.3≥ 4.8.0, < 4.8.4739.042024-07-09
CVE-2024-38081 [HIGH] CWE-59 .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
cvelistv5
CVE-2024-21409HIGHCVSS 7.3≥ 4.8.0, < 4.8.4718.02024-04-09
CVE-2024-21409 [HIGH] CWE-416 CVE-2024-21409: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2024-29059HIGHCVSS 7.5KEVPoC≥ 4.8.0, < 4.8.04690.022024-03-23
CVE-2024-29059 [HIGH] CWE-209 CVE-2024-29059: .NET Framework Information Disclosure Vulnerability .NET Framework Information Disclosure Vulnerability
cvelistv5nvd
CVE-2024-0057CRITICALCVSS 9.8≥ 4.8.0, < 4.8.04690.022024-01-09
CVE-2024-0057 [CRITICAL] CWE-20 CVE-2024-0057: NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
cvelistv5nvd
CVE-2024-21312HIGHCVSS 7.5≥ 4.8.0, < 4.8.04690.022024-01-09
CVE-2024-21312 [HIGH] CWE-20 .NET Framework Denial of Service Vulnerability .NET Framework Denial of Service Vulnerability .NET Framework Denial of Service Vulnerability
cvelistv5
CVE-2024-0056HIGHCVSS 8.7≥ 4.8.0, < 4.8.04690.022024-01-09
CVE-2024-0056 [HIGH] CWE-319 CVE-2024-0056: Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnera Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
cvelistv5nvd
CVE-2023-36049CRITICALCVSS 9.8≥ 4.8.0, < 4.8.4682.02023-11-14
CVE-2023-36049 [CRITICAL] CWE-20 CVE-2023-36049: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2023-36560HIGHCVSS 8.8≥ 4.8.0, < 4.8.4682.02023-11-14
CVE-2023-36560 [HIGH] ASP.NET Security Feature Bypass Vulnerability ASP.NET Security Feature Bypass Vulnerability ASP.NET Security Feature Bypass Vulnerability
cvelistv5
CVE-2023-36796HIGHCVSS 7.8≥ 4.8.0, < 4.8.04667.032023-09-12
CVE-2023-36796 [HIGH] CWE-191 Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2023-36792HIGHCVSS 7.8≥ 4.8.0, < 4.8.04667.032023-09-12
CVE-2023-36792 [HIGH] CWE-190 Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2023-36793HIGHCVSS 7.8≥ 4.8.0, < 4.8.04667.032023-09-12
CVE-2023-36793 [HIGH] CWE-122 Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2023-36788HIGHCVSS 7.8≥ 4.8.0, < 4.8.04667.032023-09-12
CVE-2023-36788 [HIGH] CVE-2023-36788: .NET Framework Remote Code Execution Vulnerability .NET Framework Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2023-36794HIGHCVSS 7.8≥ 4.8.0, < 4.8.04667.022023-09-12
CVE-2023-36794 [HIGH] CWE-191 Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability Visual Studio Remote Code Execution Vulnerability
cvelistv5