CVE Vulnerabilities

CVE-2025-21176

Buffer Over-read

Published: Jan 14, 2025 | Modified: Feb 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

Weakness

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Affected Software

Name Vendor Start Version End Version
Visual_studio_2017 Microsoft 15.0 (including) 15.9.69 (excluding)
Red Hat Enterprise Linux 8 RedHat dotnet8.0-0:8.0.112-1.el8_10 *
Red Hat Enterprise Linux 8 RedHat dotnet9.0-0:9.0.102-1.el8_10 *
Red Hat Enterprise Linux 9 RedHat dotnet8.0-0:8.0.112-1.el9_5 *
Red Hat Enterprise Linux 9 RedHat dotnet9.0-0:9.0.102-1.el9_5 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat dotnet8.0-0:8.0.112-1.el9_4 *
Dotnet6 Ubuntu jammy *
Dotnet7 Ubuntu jammy *
Dotnet8 Ubuntu devel *
Dotnet8 Ubuntu jammy *
Dotnet8 Ubuntu noble *
Dotnet8 Ubuntu oracular *
Dotnet9 Ubuntu devel *
Dotnet9 Ubuntu oracular *

References