CVE-2025-55248
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-14
Last updated on: 2025-10-23
Assigner: Microsoft Corporation
Description
Description
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| linux | linux_kernel | From 5.15.160 (inc) to 5.16 (inc) |
| microsoft | .net_framework | 4.6.2 |
| microsoft | .net_framework | 4.7 |
| microsoft | .net_framework | 4.7.1 |
| microsoft | .net_framework | 4.7.2 |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2012 | * |
| microsoft | windows_server_2012 | r2 |
| microsoft | .net_framework | 4.6.2 |
| microsoft | windows_server_2008 | * |
| microsoft | windows_server_2008 | * |
| microsoft | .net_framework | 3.5.1 |
| microsoft | windows_server_2008 | r2 |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 4.8.1 |
| microsoft | windows_10_21h2 | * |
| microsoft | windows_10_22h2 | * |
| microsoft | windows_11_22h2 | * |
| microsoft | windows_11_23h2 | * |
| microsoft | windows_11_24h2 | * |
| microsoft | windows_11_25h2 | * |
| microsoft | windows_server_2022 | * |
| microsoft | windows_server_2022_23h2 | * |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 4.8 |
| microsoft | windows_10_1809 | * |
| microsoft | windows_10_1809 | * |
| microsoft | windows_10_21h2 | * |
| microsoft | windows_10_22h2 | * |
| microsoft | windows_server_2019 | * |
| microsoft | windows_server_2022 | * |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 4.7.2 |
| microsoft | windows_10_1607 | * |
| microsoft | windows_10_1607 | * |
| microsoft | windows_10_1809 | * |
| microsoft | windows_10_1809 | * |
| microsoft | windows_server_2016 | * |
| microsoft | windows_server_2019 | * |
| microsoft | .net_framework | 3.5 |
| microsoft | windows_server_2008 | * |
| microsoft | windows_server_2008 | * |
| microsoft | windows_server_2012 | * |
| microsoft | windows_server_2012 | r2 |
| microsoft | .net_framework | 3.0 |
| microsoft | windows_server_2008 | * |
| microsoft | windows_server_2008 | * |
| microsoft | .net | From 8.0.0 (inc) to 8.0.21 (exc) |
| microsoft | .net | From 9.0.0 (inc) to 9.0.10 (exc) |
| apple | macos | * |
| microsoft | windows | * |
| microsoft | visual_studio_2022 | From 17.10.0 (inc) to 17.10.20 (exc) |
| microsoft | visual_studio_2022 | From 17.12.0 (inc) to 17.12.13 (exc) |
| microsoft | visual_studio_2022 | From 17.14.0 (inc) to 17.14.17 (exc) |
| microsoft | .net_framework | 4.8 |
| microsoft | windows_10_1607 | * |
| microsoft | windows_10_1607 | * |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2012 | * |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_server_2016 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-326 | The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves inadequate encryption strength in .NET, .NET Framework, and Visual Studio, which allows an authorized attacker to disclose information over a network.
How can this vulnerability impact me? :
An authorized attacker could exploit this vulnerability to disclose sensitive information over a network, potentially leading to data exposure.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70