Miggo Logo

CVE-2025-21171: Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability

8.1

CVSS Score
3.1

Basic Information

EPSS Score
0.37623%
Published
1/14/2025
Updated
1/14/2025
KEV Status
No
Technology
TechnologyC#

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
Microsoft.NetCore.App.Runtime.linux-armnuget>= 9.0.0, < 9.0.19.0.1
Microsoft.NetCore.App.Runtime.linux-arm64nuget>= 9.0.0, < 9.0.19.0.1
Microsoft.NetCore.App.Runtime.linux-musl-armnuget>= 9.0.0, < 9.0.19.0.1
Microsoft.NetCore.App.Runtime.linux-musl-arm64nuget>= 9.0.0, < 9.0.19.0.1
Microsoft.NetCore.App.Runtime.linux-musl-x64nuget>= 9.0.0, < 9.0.19.0.1
Microsoft.NetCore.App.Runtime.linux-x64nuget>= 9.0.0, < 9.0.19.0.1
Microsoft.NetCore.App.Runtime.osx-arm64nuget>= 9.0.0, < 9.0.19.0.1
Microsoft.NetCore.App.Runtime.osx-x64nuget>= 9.0.0, < 9.0.19.0.1
Microsoft.NetCore.App.Runtime.win-armnuget>= 9.0.0, < 9.0.19.0.1
Microsoft.NetCore.App.Runtime.win-arm64nuget>= 9.0.0, < 9.0.19.0.1
Microsoft.NetCore.App.Runtime.win-x64nuget>= 9.0.0, < 9.0.19.0.1
Microsoft.NetCore.App.Runtime.win-x86nuget>= 9.0.0, < 9.0.19.0.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The provided vulnerability information does not explicitly list specific vulnerable functions, file paths, or code snippets. The advisory describes a heap-based buffer overflow (CWE-122) in .NET 9.0 runtimes, but the 'Current Vulnerable Functions' fields in all affected packages are empty. The GitHub advisory links (e.g., dotnet/runtime#111423) and NVD entry lack technical details about the underlying code flaw. Without commit diffs, patch details, or explicit function names in the provided data, it is impossible to identify the exact vulnerable functions. The vulnerability likely resides in low-level runtime components handling network requests or memory operations, but confidence in specific functions is low due to insufficient technical disclosure.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

# Mi*roso*t S**urity **visory *V*-****-***** | .N*T R*mot* *o** *x**ution Vuln*r**ility ## <* n*m*="*x**utiv*-summ*ry"></*>*x**utiv* summ*ry Mi*roso*t is r*l**sin* t*is s**urity **visory to provi** in*orm*tion **out * vuln*r**ility in .N*T *.*. T*i

Reasoning

T** provi*** vuln*r**ility in*orm*tion *o*s not *xpli*itly list sp**i*i* vuln*r**l* *un*tions, *il* p*t*s, or *o** snipp*ts. T** **visory **s*ri**s * ***p-**s** *u***r ov*r*low (*W*-***) in .N*T *.* runtim*s, *ut t** '*urr*nt Vuln*r**l* *un*tions' *i