CVE-2025-21176

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 126

Summary

CVE-2025-21176 is a newly disclosed vulnerability affecting .NET, .NET Framework, and Visual Studio. This issue allows an attacker to execute arbitrary code remotely through specially crafted requests, posing a significant security risk for affected systems. The vulnerability stems from an unchecked deserialization functionality, which can be exploited to deserialize malicious data leading to code execution. Microsoft has released patches to address this issue, and users are strongly encouraged to apply them promptly to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share