CVE-2025-21172: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21172?
CVE-2025-21172 is classified as a remote code execution vulnerability, which can allow attackers to execute arbitrary code on vulnerable systems.
How could CVE-2025-21172 impact my system?
Exploitation of CVE-2025-21172 may lead to unauthorized access, data breaches, or complete system compromise.
How do I fix CVE-2025-21172?
To remediate CVE-2025-21172, apply the latest security patches provided by Microsoft for the affected versions of Visual Studio and .NET.
Which software is affected by CVE-2025-21172?
CVE-2025-21172 affects various versions of Visual Studio 2017, 2019, 2022 and .NET 8.0, as well as .NET 9.0.
Is my version affected by CVE-2025-21172?
To determine if your version is affected by CVE-2025-21172, check if you are using Visual Studio 17.6, 17.8, 17.10, 17.12 or .NET versions 8.0 or 9.0.