CVE-2025-55247 is a local privilege escalation vulnerability in .NET, affecting both Linux and Microsoft platforms, stemming from improper link resolution before file access. With a CVSS score of 7.3 (HIGH), an authorized attacker can exploit this with low attack complexity, requiring user interaction, to achieve high confidentiality, integrity, and availability impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness despite its inactive status on the CISA KEV list.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 8.0.21CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.10CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
Oct 15, 2025dotnet: .NET Denial of Service Vulnerability
Oct 15, 2025.NET Elevation of Privilege Vulnerability
Oct 14, 2025Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability
Oct 14, 2025Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability
Oct 14, 2025Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability
Oct 14, 2025Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability
Oct 14, 2025Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability
Oct 14, 2025Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability
Oct 14, 2025Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability
Oct 14, 2025