Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
History

Fri, 13 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 13 Jun 2025 01:45:00 +0000

Type Values Removed Values Added
Description A remote code execution vulnerability in .NET 8.0 and 9.0. An attacker who can place malicious files in specific locations may trigger unintended code execution when the .NET runtime loads these files. Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
Title dotnet: .NET Remote Code Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Wed, 11 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
Description A remote code execution vulnerability in .NET 8.0 and 9.0. An attacker who can place malicious files in specific locations may trigger unintended code execution when the .NET runtime loads these files.
Title dotnet: .NET Remote Code Vulnerability
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-427
CPEs cpe:/a:redhat:enterprise_linux:8
cpe:/a:redhat:enterprise_linux:9
cpe:/o:redhat:enterprise_linux:10.0
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published: 2025-06-13T01:08:00.208Z

Updated: 2025-06-13T15:46:09.476Z

Reserved: 2025-03-21T19:09:29.816Z

Link: CVE-2025-30399

cve-icon Vulnrichment

Updated: 2025-06-13T15:46:05.733Z

cve-icon NVD

Status : Received

Published: 2025-06-13T02:15:23.430

Modified: 2025-06-13T02:15:23.430

Link: CVE-2025-30399

cve-icon Redhat

Severity : Important

Publid Date: 2025-06-10T00:00:00Z

Links: CVE-2025-30399 - Bugzilla