CVE-2025-24043

HIGH

Microsoft Windbg < 1.2502.25002.0 - Signature Verification Bypass

Title source: rule
STIX 2.1

Description

Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network.

Scores

CVSS v3 7.5
EPSS 0.0014
EPSS Percentile 33.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (4)
microsoft/windbg < 1.2502.25002.0
nuget/dotnet-debugger-extensions 0 - 9.0.607601NuGet
nuget/dotnet-dump 0 - 9.0.607501NuGet
nuget/dotnet-sos 0 - 9.0.607501NuGet
Published Mar 11, 2025
Tracked Since Feb 18, 2026