dotnet-sos
This repository contains the source code for various .NET Core runtime diagnostic tools and documents.
Activity
- Latest release
- 1w ago
- Total releases
- 43
- Cadence
- ~44 days
- Last 12 months
- 3
Reach
- Stars
- 1.3k
Details
- License
- MIT
- First release
- Apr 30, 2019
| Version | Released | |
|---|---|---|
10.0.731102
major
| ||
9.0.661903
patch
| ||
9.0.652701
patch
| ||
9.0.621003
patch
| ||
9.0.607501
patch
| ||
9.0.553101
major
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
8.0.547301
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
8.0.532401
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
8.0.510501
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
8.0.505301
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
8.0.452401
major
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
7.0.447801
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
7.0.442301
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
7.0.430602
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
7.0.421201
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
7.0.410101
major
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
6.0.351802
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
6.0.328102
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
6.0.327302
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
6.0.320703
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
6.0.257301
major
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
5.0.251802
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
5.0.248003
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
5.0.236902
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
5.0.227602
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
5.0.221401
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
5.0.217401
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
5.0.160202
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
5.0.152202
major
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
3.1.141901
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
3.1.137102
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
3.1.135903
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
3.1.122203
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
3.1.120604
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
3.1.57502
minor
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
3.0.52901
patch
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
3.0.47001
initial
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
3.0.0-preview9.19454.1
pre
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
3.0.0-preview8.19412.1
pre
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
3.0.0-preview7.19365.2
pre
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
1.0.4-preview6.19311.1
pre
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
1.0.3-preview5.19251.2
pre
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev | ||
1.0.3-preview5.19228.1
pre
1 CVE
CVE-2025-24043
GHSA-hpw7-8qpc-34p3
Mar 07, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in WinDbg. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. Improper verification of cryptographic signature in SOS allows an authorized attacker to execute code over a network resulting in Remote Code Execution. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/346 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below WinDbg WinDbgPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- dotnet-sos | < 9.0.607501 | 9.0.607501 dotnet-dump | < 9.0.557512 | 9.0.607501 dotnet-debugger-extensions | 9.0.557512 | 9.0.607601 Advisory FAQHow do I know if I am affected?If you you are using the affected version listed in affected packages, you're exposed to the vulnerability. How do I fix the issue?
Other InformationReporting Security IssuesIf you have found a potential security issue, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (March 06, 2024): Advisory published. Version 1.0 Last Updated 2025-03-06 Affected versions
1.0.0
3.0.47001
3.0.52901
3.1.120604
3.1.122203
3.1.135903
3.1.137102
3.1.141901
3.1.57502
5.0.152202
5.0.160202
5.0.217401
+ 21 more Show less
5.0.221401
5.0.227602
5.0.236902
5.0.248003
5.0.251802
6.0.257301
6.0.320703
6.0.327302
6.0.328102
6.0.351802
7.0.410101
7.0.421201
7.0.430602
7.0.442301
7.0.447801
8.0.452401
8.0.505301
8.0.510501
8.0.532401
8.0.547301
9.0.553101
Fixed in
9.0.607501
References Updated Mar 12, 2025 · Source: OSV.dev |