CVE-2025-55248
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-14

Last updated on: 2025-10-23

Assigner: Microsoft Corporation

Description
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-14
Last Modified
2025-10-23
Generated
2026-05-07
AI Q&A
2025-10-14
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 61 associated CPEs
Vendor Product Version / Range
linux linux_kernel From 5.15.160 (inc) to 5.16 (inc)
microsoft .net_framework 4.6.2
microsoft .net_framework 4.7
microsoft .net_framework 4.7.1
microsoft .net_framework 4.7.2
microsoft windows_server_2008 r2
microsoft windows_server_2012 *
microsoft windows_server_2012 r2
microsoft .net_framework 4.6.2
microsoft windows_server_2008 *
microsoft windows_server_2008 *
microsoft .net_framework 3.5.1
microsoft windows_server_2008 r2
microsoft .net_framework 3.5
microsoft .net_framework 4.8.1
microsoft windows_10_21h2 *
microsoft windows_10_22h2 *
microsoft windows_11_22h2 *
microsoft windows_11_23h2 *
microsoft windows_11_24h2 *
microsoft windows_11_25h2 *
microsoft windows_server_2022 *
microsoft windows_server_2022_23h2 *
microsoft .net_framework 3.5
microsoft .net_framework 4.8
microsoft windows_10_1809 *
microsoft windows_10_1809 *
microsoft windows_10_21h2 *
microsoft windows_10_22h2 *
microsoft windows_server_2019 *
microsoft windows_server_2022 *
microsoft .net_framework 3.5
microsoft .net_framework 4.7.2
microsoft windows_10_1607 *
microsoft windows_10_1607 *
microsoft windows_10_1809 *
microsoft windows_10_1809 *
microsoft windows_server_2016 *
microsoft windows_server_2019 *
microsoft .net_framework 3.5
microsoft windows_server_2008 *
microsoft windows_server_2008 *
microsoft windows_server_2012 *
microsoft windows_server_2012 r2
microsoft .net_framework 3.0
microsoft windows_server_2008 *
microsoft windows_server_2008 *
microsoft .net From 8.0.0 (inc) to 8.0.21 (exc)
microsoft .net From 9.0.0 (inc) to 9.0.10 (exc)
apple macos *
microsoft windows *
microsoft visual_studio_2022 From 17.10.0 (inc) to 17.10.20 (exc)
microsoft visual_studio_2022 From 17.12.0 (inc) to 17.12.13 (exc)
microsoft visual_studio_2022 From 17.14.0 (inc) to 17.14.17 (exc)
microsoft .net_framework 4.8
microsoft windows_10_1607 *
microsoft windows_10_1607 *
microsoft windows_server_2008 r2
microsoft windows_server_2012 *
microsoft windows_server_2012 r2
microsoft windows_server_2016 *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-326 The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability involves inadequate encryption strength in .NET, .NET Framework, and Visual Studio, which allows an authorized attacker to disclose information over a network.


How can this vulnerability impact me? :

An authorized attacker could exploit this vulnerability to disclose sensitive information over a network, potentially leading to data exposure.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart