.NET and Visual Studio Remote Code Execution Vulnerability
Published Jan 14, 2025
7.5
HIGHCVSS 3.1
EPSS 1.81%
Description
.NET and Visual Studio Remote Code Execution Vulnerability
Affected products
-
Affected
- ≥ 14.0.0, < 14.0.24252.2
- Vendor Microsoft Product Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) Defaultunknown
Affected
- ≥ 15.9.0, < 15.9.69
- Vendor Microsoft Product Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) Defaultunknown
Affected
- ≥ 16.11.0, < 16.11.43
-
Affected
- ≥ 17.10.0, < 17.10.10
-
Affected
- ≥ 17.12.0, < 17.12.4
-
Affected
- ≥ 17.6.0, < 17.6.22
-
Affected
- ≥ 17.8.0, < 17.8.17
-
Affected
- ≥ 8.0.0, < 8.0.12
- ≥ 9.0.0, < 9.0.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Microsoft | Microsoft Visual Studio 2015 Update 3 | unknown | Affected
|
| Microsoft | Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) | unknown | Affected
|
| Microsoft | Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) | unknown | Affected
|
| Microsoft | Microsoft Visual Studio 2022 version 17.10 | unknown | Affected
|
| Microsoft | Microsoft Visual Studio 2022 version 17.12 | unknown | Affected
|
| Microsoft | Microsoft Visual Studio 2022 version 17.6 | unknown | Affected
|
| Microsoft | Microsoft Visual Studio 2022 version 17.8 | unknown | Affected
|
| Microsoft | n/a | unknown | Affected
|
Configuration 1
Configuration 2
- ≥ 15.0 · ≤ 15.8
- ≥ 16.0 · ≤ 16.10
- ≥ 17.6.0 · < 17.6.22
- ≥ 17.8.0 · < 17.8.17
- ≥ 17.10.0 · < 17.10.10
- ≥ 17.12.0 · < 17.12.4
No data.
Red Hat Enterprise Linux 8
dotnet8.0-0:8.0.112-1.el8_10
Fixed · RHSA-2025:0381
Red Hat Enterprise Linux 8
dotnet9.0-0:9.0.102-1.el8_10
Fixed · RHSA-2025:0382
Red Hat Enterprise Linux 9
dotnet8.0-0:8.0.112-1.el9_5
Fixed · RHBA-2025:0304
Red Hat Enterprise Linux 9
dotnet9.0-0:9.0.102-1.el9_5
Fixed · RHBA-2025:0305
Red Hat Enterprise Linux 9.4 Extended Update Support
dotnet8.0-0:8.0.112-1.el9_4
Fixed · RHSA-2025:0532
Red Hat Enterprise Linux 10
dotnet8.0
Not affected
Red Hat Enterprise Linux 10
dotnet9.0
Not affected
Red Hat Enterprise Linux 9
dotnet6.0
Out of support scope
Red Hat Enterprise Linux 9
dotnet7.0
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | dotnet8.0-0:8.0.112-1.el8_10 | Fixed | RHSA-2025:0381 |
| Red Hat Enterprise Linux 8 | dotnet9.0-0:9.0.102-1.el8_10 | Fixed | RHSA-2025:0382 |
| Red Hat Enterprise Linux 9 | dotnet8.0-0:8.0.112-1.el9_5 | Fixed | RHBA-2025:0304 |
| Red Hat Enterprise Linux 9 | dotnet9.0-0:9.0.102-1.el9_5 | Fixed | RHBA-2025:0305 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | dotnet8.0-0:8.0.112-1.el9_4 | Fixed | RHSA-2025:0532 |
| Red Hat Enterprise Linux 10 | dotnet8.0 | Not affected | n/a |
| Red Hat Enterprise Linux 10 | dotnet9.0 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dotnet6.0 | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | dotnet7.0 | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects .NET Framework as shipped with all versions of RHEL. However, this flaw is not known to be exploitable under any supported scenario. ``` .NET 6.0 for RHEL-8, RHEL-9 and RHIVOS has reached its End of Life as of November 12, 2024, and is no longer supported. No fixes will be provided for this stream. For additional information about lifecycle for .NET on Red Hat Enterprise Linux, please refer to: https://access.redhat.com/support/policy/updates/net-core. ```
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
References (9)
- https://access.redhat.com/security/cve/CVE-2025-21172 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2337927 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-0074 Advisory
- https://github.com/advisories/GHSA-jjcv-wr2g-4rv4 Advisory
- https://github.com/dotnet/runtime/security/advisories/GHSA-jjcv-wr2g-4rv4
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21172 vendor-advisorypatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-21172
- https://www.cve.org/CVERecord?id=CVE-2025-21172
- https://www.herodevs.com/vulnerability-directory/cve-2025-21172
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub