<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:30:41.169913+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:0382</id>
    <title>ALSA-2025:0382 — Important: .NET 9.0 security update</title>
    <updated>2026-10-02T20:30:41.185806+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: aspnetcore-runtime-9.0, AlmaLinux:8: aspnetcore-runtime-dbg-9.0, AlmaLinux:8: aspnetcore-targeting-pack-9.0, AlmaLinux:8: dotnet, AlmaLinux:8: dotnet-apphost-pack-9.0, AlmaLinux:8: dotnet-host, AlmaLinux:8: dotnet-hostfxr-9.0, AlmaLinux:8: dotnet-runtime-9.0, AlmaLinux:8: dotnet-runtime-dbg-9.0, AlmaLinux:8: dotnet-sdk-9.0 and 6 more</p>
<p>.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.</p>
<p>New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.102 and .NET Runtime 9.0.1.</p>
<p>Security Fix(es):</p>
<p>* dotnet: .NET Remote Code Execution Vulnerability (CVE-2025-21171)
  * dotnet: .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21172)
  * dotnet: .NET Elevation of Privilege Vulnerability (CVE-2025-21173)
  * dotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21176)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Security Fix(es):</p>
<p>* dotnet: .NET Elevation of Privilege Vulnerability (CVE-2025-21173)
  * dotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21176)
  * dotnet: .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21172)
  * dotnet: .NET Remote Code Execution Vulnerability (CVE-2025-21171)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:0382"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-00434</id>
    <title>bdu:2025-00434</title>
    <updated>2026-10-02T20:30:41.185939+00:00</updated>
    <content>bdu:2025-00434</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-00434"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-dotnet-2025-21171</id>
    <title>BIT-dotnet-2025-21171 — .NET Remote Code Execution Vulnerability</title>
    <updated>2026-10-02T20:30:41.185967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: dotnet</p>
<p>.NET Remote Code Execution Vulnerability</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-dotnet-2025-21171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0039</id>
    <title>certfr-2025-avi-0039 — De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaqua…</title>
    <updated>2026-10-02T20:30:41.185999+00:00</updated>
    <content>certfr-2025-avi-0039</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0039"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-04177</id>
    <title>cnvd-2025-04177</title>
    <updated>2026-10-02T20:30:41.186024+00:00</updated>
    <content>cnvd-2025-04177</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-04177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326013</id>
    <title>EUVD-2026-326013</title>
    <updated>2026-10-02T20:30:41.186042+00:00</updated>
    <content>EUVD-2026-326013</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21171</id>
    <title>fkie_cve-2025-21171</title>
    <updated>2026-10-02T20:30:41.186059+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>.NET Remote Code Execution Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-21171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p54p-p3qm-8vgj</id>
    <title>GHSA-p54p-p3qm-8vgj — Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability</title>
    <updated>2026-10-02T20:30:41.186088+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: Microsoft.NetCore.App.Runtime.linux-arm, NuGet: Microsoft.NetCore.App.Runtime.linux-arm64, NuGet: Microsoft.NetCore.App.Runtime.linux-musl-arm, NuGet: Microsoft.NetCore.App.Runtime.linux-musl-arm64, NuGet: Microsoft.NetCore.App.Runtime.linux-musl-x64, NuGet: Microsoft.NetCore.App.Runtime.linux-x64, NuGet: Microsoft.NetCore.App.Runtime.osx-arm64, NuGet: Microsoft.NetCore.App.Runtime.osx-x64, NuGet: Microsoft.NetCore.App.Runtime.win-arm, NuGet: Microsoft.NetCore.App.Runtime.win-arm64 and 2 more</p>
<p># Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability</p>
<p>## &lt;a name="executive-summary"&gt;&lt;/a&gt;Executive summary</p>
<p>Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.</p>
<p>An attacker could exploit this vulnerability by sending a specially crafted request to the vulnerable web server.</p>
<p>## Announcement</p>
<p>Announcement for this issue can be found at https://github.com/dotnet/runtime/issues/111423</p>
<p>## &lt;a name="mitigation-factors"&gt;&lt;/a&gt;Mitigation factors</p>
<p>Microsoft has not identified any mitigating factors for this vulnerability.</p>
<p>## &lt;a name="affected-software"&gt;&lt;/a&gt;Affected software</p>
<p>* Any .NET 9.0 application running on .NET 9.0.0 or earlier.</p>
<p>## &lt;a name="affected-packages"&gt;&lt;/a&gt;Affected Packages</p>
<p>The vulnerability affects any Microsoft .NET project if it uses any of affected packages versions listed below</p>
<p>### &lt;a name=".NET 9"&gt;&lt;/a&gt;.NET 9
Package name | Affected version | Patched version
------------ | ---------------- | -------------------------
[Microsoft.NetCore.App.Runtime.linux-arm](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-arm)               | &gt;= 9.0.0, &lt; 9.0.1 | 9.0.1
[Microsoft.NetCore.App.Runtime.linux-arm64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-arm64)           | &gt;= 9.0.0, &lt; 9.0.1 | 9.0.1
[Microsoft.NetCore.App.Runtime.linu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p54p-p3qm-8vgj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21171</id>
    <title>msrc_CVE-2025-21171 — .NET Remote Code Execution Vulnerability</title>
    <updated>2026-10-02T20:30:41.186208+00:00</updated>
    <content>msrc_CVE-2025-21171</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-21171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:0305</id>
    <title>RHBA-2025:0305 — Red Hat Bug Fix Advisory: .NET 9.0 bug fix and enhancement update</title>
    <updated>2026-10-02T20:30:41.186237+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dotnet: .NET Remote Code Execution Vulnerability dotnet: .NET and Visual Studio Remote Code Execution Vulnerability dotnet: .NET Elevation of Privilege Vulnerability dotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:0305"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21171</id>
    <title>UBUNTU-CVE-2025-21171</title>
    <updated>2026-10-02T20:30:41.186272+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: dotnet7</p>
<p>.NET Remote Code Execution Vulnerability</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0093</id>
    <title>WID-SEC-W-2025-0093 — Microsoft Developer Tools: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:30:41.186298+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio 2017, Microsoft .NET Framework, Microsoft Windows Server 2012, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2016, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Microsoft Visual Studio 2019, Microsoft Visual Studio 2022 und Microsoft Windows ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen und vertrauliche Informationen preiszugeben.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0093"/>
  </entry>
</feed>
