Showing 25 vulnerabilities on this page for .NET 9.0

Signals CISA KEV Ransomware Nuclei
Microsoft vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Microsoft QUIC Information Disclosure Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Microsoft QUIC. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/426 ## CVSS Details - **Ver

CWE-416Aug 11, 2026
CVSS7.5v3.1EPSS1.14%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Core Remote Code Execution Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/432 ## CVSS Details - **Versi

CWE-787Aug 11, 2026
CVSS7.8v3.1EPSS0.387%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Elevation of Privilege Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/430 ## CVSS D

CWE-122CWE-190Aug 11, 2026
CVSS7.8v3.1EPSS0.405%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Elevation of Privilege Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/431 ## CVSS Details - **Version:

CWE-122CWE-787Aug 11, 2026
CVSS7.8v3.1EPSS0.405%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Elevation of Privilege Vulnerability

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

CWE-190Aug 11, 2026
CVSS7.8v3.1EPSS0.401%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Elevation of Privilege Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET diagnostics IPC. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A missing error check in .NET causes an improper ACL to be applied to a shared resource, resulting in local elevation of privilege. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issue

CWE-248CWE-252Aug 11, 2026
CVSS7.8v3.1EPSS0.295%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Information Disclosure Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A specially crafted document parsed in .NET can trigger the inclusion of functionality from an untrusted control sphere, allowing an unauthorized attacker to disclose information over a network. ## Announcement Announcement fo

CVSS6.5v3.1EPSS0.779%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Denial of Service Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.WebSockets. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/428 ## CVSS Detail

CWE-606Aug 11, 2026
CVSS7.5v3.1EPSS1.08%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Information Disclosure Vulnerability

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

CWE-212Aug 11, 2026
CVSS5.9v3.1EPSS0.558%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Security Feature Bypass Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.HttpListener. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. ## Announcement Announcement for this issue can be found at https://

CWE-444Aug 11, 2026
CVSS5.9v3.1EPSS0.721%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Framework Remote Code Execution Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An integer overflow or wraparound in .NET allows an unauthorized attacker to execute code locally. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/434 ## CVSS Details

CWE-190Aug 11, 2026
CVSS7.0v3.1EPSS0.336%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:.NET SMTP Client Spoofing Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SMTP client (System.Net.Mail). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A spoofing vulnerability exists in the SMTP client implementation (System.Net.Mail) in .NET 8, .NET 9, and .NET 10, where an attacker can spoof messages during message routing. ## Announcement Announcement for this issue ca

CWE-116Jul 14, 2026
CVSS6.5v3.1EPSS0.55%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Denial of Service Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET HTTP client (System.Net.Http). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in .NET 8, .NET 9, and .NET 10 where an attacker can exploit the HTTP/2 protocol to cause an out-of-memory condition. ## Announcement Announcement for this issue can be found at http

CWE-770Jul 14, 2026
CVSS7.5v3.1EPSS0.84%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Framework Elevation of Privilege Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation (WPF). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An elevation of privilege vulnerability exists in Windows Presentation Foundation (WPF) in .NET 8, .NET 9, and .NET 10 when parsing specially crafted XAML input. An attacker who successfully exploits this vulnerability cou

CWE-94Jul 14, 2026
CVSS7.8v3.1EPSS0.29%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Remote Code Execution Vulnerability

Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

CWE-502Jul 14, 2026
CVSS7.8v3.1EPSS0.918%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Framework Denial of Service Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in the XML encryption implementation (EncryptedXml) in .NET 8, .NET 9, and .NET 10. An attacker could exploit this vulnerability by supplying crafted encrypted XML

CWE-770Jul 14, 2026
CVSS7.5v3.1EPSS0.84%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Framework Remote Code Execution Vulnerability

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

CWE-502CWE-693Jul 14, 2026
CVSS7.8v3.1EPSS0.949%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Security Feature Bypass Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A security feature bypass vulnerability exists in .NET 8, .NET 9, and .NET 10 when processing TLS/SSL connections. An attacker can exploit the SslStream implementation to bypass authorization checks during secure communicatio

CVSS8.2v3.1EPSS0.551%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Framework Denial of Service Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in the XML encryption implementation (EncryptedXml) in .NET 8, .NET 9, and .NET 10. An attacker could exploit this vulnerability by supplying crafted encrypted XML

CWE-121Jul 14, 2026
CVSS7.5v3.1EPSS0.84%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Tampering Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SDK (Microsoft.NET.Build.Containers). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A tampering vulnerability exists in the .NET SDK (.NET 8, .NET 9, and .NET 10) container image build process which could allow a local attacker to inject resources that could be incorporated into container images built

CWE-345CWE-59Jul 14, 2026
CVSS7.0v3.1EPSS0.236%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Denial of Service Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in the XML encryption implementation (EncryptedXml) in .NET 8, .NET 9, and .NET 10. An attacker could exploit this vulnerability by supplying crafted encrypted XML

CWE-770Jul 14, 2026
CVSS7.5v3.1EPSS0.604%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Framework Denial of Service Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in .NET 8, .NET 9, and .NET 10 when processing TLS handshakes. An attacker can send a malformed request and cause application to crash or become unresponsive. ## Announcement Announc

CWE-1287Jul 14, 2026
CVSS7.5v3.1EPSS0.634%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Security Feature Bypass Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A security feature bypass vulnerability exists in the XML encryption implementation (EncryptedXml) in .NET 8, .NET 9, and .NET 10. An attacker could exploit this vulnerability to bypass encryption protecti

CWE-345CWE-347Jul 14, 2026
CVSS8.1v3.1EPSS0.216%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ASP.NET Core Elevation of Privilege Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core Negotiate Authentication (Microsoft.AspNetCore.Authentication.Negotiate). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An elevation of privilege vulnerability exists in the ASP.NET Core Negotiate authentication handler in .NET 8, .NET 9, and .NET 10 due to improper parsing. ## Announcement

CVSS8.8v3.1EPSS0.736%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

.NET Denial of Service Vulnerability

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML processing (System.Security.Cryptography.Xml, System.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in .NET 8, .NET 9, and .NET 10 related to XML processing. An attacker can exploit XML encryption handling in XML parsing to cause excessive resource con

CWE-770Jul 14, 2026
CVSS7.5v3.1EPSS1.03%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX