CVE-2025-21171: .NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Microsoft.NetCore.App.Runtime.win-x86to a version that resolves this vulnerability.Fixed in 9.0.1 - Upgrade
Upgrade
nuget/Microsoft.NetCore.App.Runtime.win-x64to a version that resolves this vulnerability.Fixed in 9.0.1 - Upgrade
Upgrade
nuget/Microsoft.NetCore.App.Runtime.win-arm64to a version that resolves this vulnerability.Fixed in 9.0.1 - Upgrade
Upgrade
nuget/Microsoft.NetCore.App.Runtime.win-armto a version that resolves this vulnerability.Fixed in 9.0.1 - Upgrade
Upgrade
nuget/Microsoft.NetCore.App.Runtime.osx-x64to a version that resolves this vulnerability.Fixed in 9.0.1 - Upgrade
Upgrade
nuget/Microsoft.NetCore.App.Runtime.osx-arm64to a version that resolves this vulnerability.Fixed in 9.0.1 - Upgrade
Upgrade
nuget/Microsoft.NetCore.App.Runtime.linux-x64to a version that resolves this vulnerability.Fixed in 9.0.1 - Upgrade
Upgrade
nuget/Microsoft.NetCore.App.Runtime.linux-musl-x64to a version that resolves this vulnerability.Fixed in 9.0.1 - Upgrade
Upgrade
nuget/Microsoft.NetCore.App.Runtime.linux-musl-arm64to a version that resolves this vulnerability.Fixed in 9.0.1 - Upgrade
Upgrade
nuget/Microsoft.NetCore.App.Runtime.linux-musl-armto a version that resolves this vulnerability.Fixed in 9.0.1 - Upgrade
Upgrade
nuget/Microsoft.NetCore.App.Runtime.linux-arm64to a version that resolves this vulnerability.Fixed in 9.0.1 - Upgrade
Upgrade
nuget/Microsoft.NetCore.App.Runtime.linux-armto a version that resolves this vulnerability.Fixed in 9.0.1 - Upgrade
Upgrade
Microsoft .NET 9.0 Runtime/SDKto a version that resolves this vulnerability.Fixed in 9.0.1Patch CVE-2025-21171 - Upgrade
Upgrade
Microsoft.NetCore.App.Runtime (RID osx-arm64 shown)to a version that resolves this vulnerability.Fixed in 9.0.1Patch CVE-2025-21171 - Operational
After installing the updated .NET 9.0 runtime or SDK, restart your apps for the update to take effect.
- Operational
For self-contained applications targeting impacted versions, recompile and redeploy the applications after installing the updated .NET 9.0 runtime or SDK.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21171?
CVE-2025-21171 is classified as a remote code execution vulnerability that can lead to significant security risks.
How do I fix CVE-2025-21171?
To resolve CVE-2025-21171, you should update to the latest patched version of Visual Studio 2022 or .NET 9.0 depending on your installation.
Which versions are affected by CVE-2025-21171?
CVE-2025-21171 affects specific versions of Visual Studio 2022 (17.6, 17.10, 17.12, 17.8) and .NET 9.0 on Windows, Mac, and Linux.
What are the potential impacts of CVE-2025-21171?
Exploitation of CVE-2025-21171 may allow an attacker to execute arbitrary code on the affected system.
Is there a workaround for CVE-2025-21171?
There are currently no specific workarounds for CVE-2025-21171; applying the latest security updates is recommended.