Описание
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
A remote code execution vulnerability in .NET 8.0 and 9.0. An attacker who can place malicious files in specific locations may trigger unintended code execution when the .NET runtime loads these files.
Отчет
This vulnerability is Important because it allows remote code execution at the runtime level, targeting the fundamental assembly loading mechanism of .NET. Unlike moderate flaws that may require complex chaining or rely on user interaction, this issue can be exploited simply by placing malicious files in specific directories that .NET probes during execution.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don’t meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 9 | dotnet6.0 | Not affected | ||
Red Hat Enterprise Linux 9 | dotnet7.0 | Not affected | ||
Red Hat Enterprise Linux 10 | dotnet8.0 | Fixed | RHSA-2025:8814 | 11.06.2025 |
Red Hat Enterprise Linux 10 | dotnet9.0 | Fixed | RHSA-2025:8816 | 11.06.2025 |
Red Hat Enterprise Linux 8 | dotnet8.0 | Fixed | RHSA-2025:8812 | 11.06.2025 |
Red Hat Enterprise Linux 8 | dotnet9.0 | Fixed | RHSA-2025:8815 | 11.06.2025 |
Red Hat Enterprise Linux 9 | dotnet8.0 | Fixed | RHSA-2025:8813 | 11.06.2025 |
Red Hat Enterprise Linux 9 | dotnet9.0 | Fixed | RHSA-2025:8817 | 11.06.2025 |
Red Hat Enterprise Linux 9.4 Extended Update Support | dotnet8.0 | Fixed | RHSA-2025:9066 | 16.06.2025 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability
EPSS
7.5 High
CVSS3