Cyber Posture

CVE-2025-21173

High

Published: 14 January 2025

Published
14 January 2025
Modified
06 May 2025
KEV Added
Patch
CVSS Score 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0200 83.7th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

.NET Elevation of Privilege Vulnerability

Security Summary

CVE-2025-21173 is an elevation of privilege vulnerability in .NET, published on 2025-01-14, with a CVSS v3.1 base score of 7.3 (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). It is associated with CWE-379 and lacks additional NVD CWE details. The flaw allows unauthorized privilege escalation within .NET environments.

A local attacker with low privileges (PR:L) can exploit this vulnerability with low attack complexity (AC:L), though it requires user interaction (UI:R). Successful exploitation enables high-impact consequences across confidentiality, integrity, and availability (C:H/I:H/A:H), typically resulting in privilege escalation on the affected system.

Microsoft's Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21173 provides details on mitigation and patching. Additional vulnerability information is available at https://www.herodevs.com/vulnerability-directory/cve-2025-21173.

Details

CWE(s)
CWE-379NVD-CWE-noinfo

Affected Products

microsoft
visual studio 2022
17.6.0 — 17.6.22 · 17.8.0 — 17.8.17 · 17.10.0 — 17.10.10
microsoft
.net
8.0.0, 9.0.0

References