CVE-2025-21171 is a high-severity Remote Code Execution vulnerability affecting .NET on Apple, Linux, and Microsoft platforms. Exploitation requires high attack complexity and user interaction, but successful attacks could lead to complete compromise of confidentiality, integrity, and availability. While not currently in CISA's KEV catalog, its recent disclosure in Microsoft's January 2025 Patch Tuesday has garnered significant media attention, though no public exploit code or active exploitation has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:9.0.0:*:*:*:*:*:*:* | ||
7.5CPE matchmatch criteria | cpe:2.3:a:microsoft:powershell:7.5:*:*:*:*:*:*:* | ||
>= 17.6.0, < 17.6.22CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.8.0, < 17.8.17CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.10.0, < 17.10.10CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
Jan 14, 2025dotnet: .NET Remote Code Execution Vulnerability
Jan 14, 2025.NET Remote Code Execution Vulnerability
Jan 14, 2025