CVE-2025-21173 is a .NET Elevation of Privilege vulnerability affecting various Microsoft and Linux products, including .NET, Linux Kernel, and Visual Studio 2022. With a CVSS score of 7.3 (HIGH), successful exploitation could lead to high confidentiality, integrity, and availability impacts, requiring local access and user interaction. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, with only one article mentioning it in the context of Microsoft's January 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.6.0, < 17.6.22CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.8.0, < 17.8.17CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.10.0, < 17.10.10CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.12.0, < 17.12.4CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
8.0.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:8.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.