PT-2025-36468 · Microsoft+1 · Asp.Net 9.0+3
Published
2025-09-08
·
Updated
2025-10-02
·
CVE-2025-36854
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
EOL ASP.NET versions 6.0.0 through 6.0.36
EOL ASP.NET versions 8.0.0 through 8.0.8
EOL ASP.NET versions 9.0.0-preview.1.24081.5 through 9.0.0.RC.1
Description:
A race condition may occur when closing an HTTP/3 stream while application code is writing to the response body, potentially leading to a use-after-free condition and resulting in Remote Code Execution. Use-after-free occurs when memory is reused or referenced after it has been freed, potentially leading to invalid operations if the memory has been reallocated. Self-contained applications targeting any of the impacted versions are also vulnerable and require recompilation and redeployment.
Recommendations:
EOL ASP.NET version 6.0.0 through 6.0.36: Recompile and redeploy self-contained applications.
EOL ASP.NET version 8.0.0 through 8.0.8: Recompile and redeploy self-contained applications.
EOL ASP.NET version 9.0.0-preview.1.24081.5 through 9.0.0.RC.1: Recompile and redeploy self-contained applications.
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asp.Net 6.0
Asp.Net 8.0
Asp.Net 9.0
Red Os