PT-2025-36468 · Microsoft+1 · Asp.Net 9.0+3

Published

2025-09-08

·

Updated

2025-10-02

·

CVE-2025-36854

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: EOL ASP.NET versions 6.0.0 through 6.0.36 EOL ASP.NET versions 8.0.0 through 8.0.8 EOL ASP.NET versions 9.0.0-preview.1.24081.5 through 9.0.0.RC.1
Description: A race condition may occur when closing an HTTP/3 stream while application code is writing to the response body, potentially leading to a use-after-free condition and resulting in Remote Code Execution. Use-after-free occurs when memory is reused or referenced after it has been freed, potentially leading to invalid operations if the memory has been reallocated. Self-contained applications targeting any of the impacted versions are also vulnerable and require recompilation and redeployment.
Recommendations: EOL ASP.NET version 6.0.0 through 6.0.36: Recompile and redeploy self-contained applications. EOL ASP.NET version 8.0.0 through 8.0.8: Recompile and redeploy self-contained applications. EOL ASP.NET version 9.0.0-preview.1.24081.5 through 9.0.0.RC.1: Recompile and redeploy self-contained applications.

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2025-12583
CVE-2025-36854

Affected Products

Asp.Net 6.0
Asp.Net 8.0
Asp.Net 9.0
Red Os