CNNVD-202509-1088 Information

CNNVD ID

CNNVD-202509-1088

CVE-2025-36855

  • CNNVD Published: 2025-09-08

Description (Chinese)

Microsoft .NET是美国微软(Microsoft)公司的一个致力于敏捷软件开发、快速应用开发、平台无关性和网络透明化的软件框架。 Microsoft .NET存在安全漏洞,该漏洞源于DiaSymReader.dll在处理符号数据时未校验长度,导致越界读取。

Description (English)

Microsoft .NET is a software framework dedicated to agile software development, rapid application development, platform non-relevance and network transparency for Microsoft (MSC) in the United States. Microsoft NET had a security loophole, which originated in DiaSymReader.dll, which did not verify the length of the symbol data processing, resulting in cross-border reading.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

微软

Published

2025-09-08

Last Modified

2026-02-24

References

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21176 https://www.herodevs.com/vulnerability-directory/cve-2025-21176

Patch

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21176

Share on: