CVE-2025-36855

A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer. This issue affects EOL ASP.NET 6.0.0 <= 6.0.36 as represented in this CVE, as well as 8.0.0 <= 8.0.11 & <= 9.0.0 as represented in CVE-2025-21176. Additionally, if you've deployed self-contained applications https://docs.microsoft.com/dotnet/core/deploying/#self-contained-deployments-scd  targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry.
Configurations

No configuration.

History

08 Sep 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-08 14:15

Updated : 2025-09-08 16:25


NVD link : CVE-2025-36855

Mitre link : CVE-2025-36855

CVE.ORG link : CVE-2025-36855


JSON object : View

Products Affected

No product.

CWE
CWE-126

Buffer Over-read