Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-55247

24
FAUCET Score

CVE-2025-55247 is a local privilege escalation vulnerability in .NET, affecting both Linux and Microsoft platforms, stemming from improper link resolution before file access. With a CVSS score of 7.3 (HIGH), an authorized attacker can exploit this with low attack complexity, requiring user interaction, to achieve high confidentiality, integrity, and availability impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness despite its inactive status on the CISA KEV list.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.0.0, < 8.0.21CPE matchmatch criteria
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.0.10CPE matchmatch criteria
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.3
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.56%
Probability of exploitation in next 30 days
EPSS Percentile
43.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0056 is in the 74th percentile among its peer group of 759 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (38)

microsoftpatch availablevia msrc
Product: .NET 8.0 installed on LinuxFixed in: 8.0.21
View patch
microsoftpatch availablevia msrc
Product: .NET 9.0 installed on LinuxFixed in: 9.0.10
View patch
nugetpatch availablevia ghsa
Product: Microsoft.Build.Tasks.CoreFixed in: 17.12.50
nugetpatch availablevia ghsa
Product: Microsoft.Build.Tasks.CoreFixed in: 17.11.48
nugetpatch availablevia ghsa
Product: Microsoft.Build.Tasks.CoreFixed in: 17.10.46
nugetpatch availablevia ghsa
Product: Microsoft.Build.Tasks.CoreFixed in: 17.8.43
nugetpatch availablevia ghsa
Product: Microsoft.BuildFixed in: 18.0.0-preview-25476-107
nugetpatch availablevia ghsa
Product: Microsoft.BuildFixed in: 17.14.28
nugetpatch availablevia ghsa
Product: Microsoft.BuildFixed in: 17.12.50
nugetpatch availablevia ghsa
Product: Microsoft.Build.Tasks.CoreFixed in: 18.0.0-preview-25476-107
nugetpatch availablevia ghsa
Product: Microsoft.BuildFixed in: 17.10.46
nugetpatch availablevia ghsa
Product: Microsoft.BuildFixed in: 17.8.43
nugetpatch availablevia ghsa
Product: Microsoft.Build.Utilities.CoreFixed in: 18.0.0-preview-25476-107
nugetpatch availablevia ghsa
Product: Microsoft.Build.Utilities.CoreFixed in: 17.14.28
nugetpatch availablevia ghsa
Product: Microsoft.Build.Utilities.CoreFixed in: 17.12.50
nugetpatch availablevia ghsa
Product: Microsoft.Build.Utilities.CoreFixed in: 17.11.48
nugetpatch availablevia ghsa
Product: Microsoft.Build.Utilities.CoreFixed in: 17.10.46
nugetpatch availablevia ghsa
Product: Microsoft.Build.Utilities.CoreFixed in: 17.8.43
nugetpatch availablevia ghsa
Product: Microsoft.BuildFixed in: 17.11.48
nugetpatch availablevia ghsa
Product: Microsoft.Build.Tasks.CoreFixed in: 17.14.28
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: dotnet8.0-0:8.0.121-1.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: dotnet9.0-0:9.0.111-1.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: dotnet10.0-0:10.0.100~rc.2.25502.107-0.12.el10_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: dotnet8.0-0:8.0.121-1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: dotnet9.0-0:9.0.111-1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: dotnet10.0-0:10.0.100~rc.2.25502.107-0.10.el9_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: dotnet8.0-0:8.0.121-1.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: dotnet9.0-0:9.0.111-1.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: dotnet8.0-0:8.0.121-1.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.25Fixed in: devspaces/udi-rhel9:sha256:8a19af8b03b59562335b3a3f77753944c27ecbccaeda3400d0f089a6cd8d11fa
View patch
asuswrtvendor investigatingvia llm_extracted
atlassianvendor investigatingvia llm_extracted
bindvendor investigatingvia llm_extracted
View patch
fobybusvendor investigatingvia llm_extracted
View patch
intelvendor investigatingvia llm_extracted
View patch
microsoftvendor investigatingvia nvd_reference
View patch
openmeetingsvendor investigatingvia llm_extracted
View patch
vllmvendor investigatingvia llm_extracted
View patch

Vendor Advisories (10)

nugetGHSA-w3q9-fxm7-j8fqhigh

Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability

Oct 15, 2025
redhatCVE-2025-55247Moderate

dotnet: .NET Denial of Service Vulnerability

Oct 15, 2025
microsoft2025-Oct/CVE-2025-55247Important

.NET Elevation of Privilege Vulnerability

Oct 14, 2025
bindllm-bind-6579888d8755d39b

Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability

Oct 14, 2025
asuswrtllm-asuswrt-a6123cf93b82fbaa

Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability

Oct 14, 2025
vllmllm-vllm-cc92208a4b8327de

Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability

Oct 14, 2025
atlassianllm-atlassian-568b08e3726e8033

Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability

Oct 14, 2025
fobybusllm-fobybus-61bd56c0ad3bdf3e

Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability

Oct 14, 2025
intelllm-intel-e9e882f8a36fec69

Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability

Oct 14, 2025
openmeetingsllm-openmeetings-6054997b16e3485b

Microsoft Security Advisory CVE-2025-55247: .NET Denial of Service Vulnerability

Oct 14, 2025

References

msrc.microsoft.com / update-guide/vulnerability/CVE-2025-55247
Vendor Advisory