Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
<a name="executive-summary"></a>Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An attacker could exploit this vulnerability by sending a specially crafted request to the vulnerable web server.
Announcement
Announcement for this issue can be found at https://github.com/dotnet/runtime/issues/111423
<a name="mitigation-factors"></a>Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
<a name="affected-software"></a>Affected software
- Any .NET 9.0 application running on .NET 9.0.0 or earlier.
<a name="affected-packages"></a>Affected Packages
The vulnerability affects any Microsoft .NET project if it uses any of affected packages versions listed below
<a name=".NET 9"></a>.NET 9
Package name | Affected version | Patched version
------------ | ---------------- | -------------------------
Microsoft.NetCore.App.Runtime.linux-arm | >= 9.0.0, < 9.0.1 | 9.0.1
Microsoft.NetCore.App.Runtime.linux-arm64 | >= 9.0.0, < 9.0.1 | 9.0.1
Microsoft.NetCore.App.Runtime.linux-musl-arm | >= 9.0.0, < 9.0.1 | 9.0.1
Microsoft.NetCore.App.Runtime.linux-musl-arm64 | >= 9.0.0, < 9.0.1 | 9.0.1
Microsoft.NetCore.App.Runtime.linux-musl-x64 | >= 9.0.0, < 9.0.1 | 9.0.1
Microsoft.NetCore.App.Runtime.linux-x64 | >= 9.0.0, < 9.0.1 | 9.0.1
| >= 9.0.0, < 9.0.1 | 9.0.1
| >= 9.0.0, < 9.0.1 | 9.0.1
| >= 9.0.0, < 9.0.1 | 9.0.1
| >= 9.0.0, < 9.0.1 | 9.0.1
| >= 9.0.0, < 9.0.1 | 9.0.1
| >= 9.0.0, < 9.0.1 | 9.0.1