Microsoft Net 9.0 vulnerabilities

16 known vulnerabilities affecting microsoft/net_9.0.

Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-33116HIGHCVSS 7.5≥ 9.0.0, < 9.0.152026-04-14
CVE-2026-33116 [HIGH] CWE-20 CVE-2026-33116: Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-26171HIGHCVSS 7.5≥ 9.0.0, < 9.0.152026-04-14
CVE-2026-26171 [HIGH] CWE-400 CVE-2026-26171: Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a net Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-32203HIGHCVSS 7.5≥ 9.0.0, < 9.0.152026-04-14
CVE-2026-32203 [HIGH] CWE-20 CVE-2026-32203: Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny servic Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-32178HIGHCVSS 7.5≥ 9.0.0, < 9.0.152026-04-14
CVE-2026-32178 [HIGH] CWE-138 CVE-2026-32178: Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoof Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
cvelistv5nvd
CVE-2026-26127HIGHCVSS 7.5≥ 9.0.0, < 9.0.142026-03-10
CVE-2026-26127 [HIGH] CWE-125 CVE-2026-26127: Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-21218HIGHCVSS 7.5≥ 9.0.0, < 9.0.132026-02-10
CVE-2026-21218 [HIGH] CWE-166 CVE-2026-21218: Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoo Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
cvelistv5nvd
CVE-2025-55247HIGHCVSS 7.3≥ 9.0.0, < 9.0.102025-10-14
CVE-2025-55247 [HIGH] CWE-59 CVE-2025-55247: Improper link resolution before file access ('link following') in .NET allows an authorized attacker Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-55248MEDIUMCVSS 5.7≥ 9.0.0, < 9.0.102025-10-14
CVE-2025-55248 [MEDIUM] CWE-326 CVE-2025-55248: Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
cvelistv5nvd
CVE-2025-30399HIGHCVSS 7.5≥ 9.0.0, < 9.0.62025-06-13
CVE-2025-30399 [HIGH] CWE-426 CVE-2025-30399: Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
cvelistv5nvd
CVE-2025-26646HIGHCVSS 8.0≥ 9.0.0, < 9.0.52025-05-13
CVE-2025-26646 [HIGH] CWE-73 CVE-2025-26646: External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allo External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
cvelistv5nvd
CVE-2025-21176HIGHCVSS 8.8≥ 9.0.0, < 9.0.12025-01-14
CVE-2025-21176 [HIGH] CWE-126 .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21173HIGHCVSS 7.3≥ 9.0.0, < 9.0.12025-01-14
CVE-2025-21173 [HIGH] CWE-379 .NET Elevation of Privilege Vulnerability .NET Elevation of Privilege Vulnerability .NET Elevation of Privilege Vulnerability
cvelistv5
CVE-2025-21171HIGHCVSS 7.5≥ 9.0.0, < 9.0.12025-01-14
CVE-2025-21171 [HIGH] CWE-122 .NET Remote Code Execution Vulnerability .NET Remote Code Execution Vulnerability .NET Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21172HIGHCVSS 7.5≥ 9.0.0, < 9.0.12025-01-14
CVE-2025-21172 [HIGH] CWE-190 .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2024-43498CRITICALCVSS 9.8≥ 9.0.0, < 9.0.02024-11-12
CVE-2024-43498 [CRITICAL] CWE-843 CVE-2024-43498: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2024-43499HIGHCVSS 7.5≥ 9.0.0, < 9.0.02024-11-12
CVE-2024-43499 [HIGH] CWE-409 CVE-2024-43499: .NET and Visual Studio Denial of Service Vulnerability .NET and Visual Studio Denial of Service Vulnerability
cvelistv5nvd