CVE-2025-36855HIGH 8.8EPSS p49.0%

CVE-2025-36855CVE-2025-36855

Description

A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer. This issue affects EOL ASP.NET 6.0.0 <= 6.0.36 as represented in this CVE, as well as 8.0.0 <= 8.0.11 & <= 9.0.0 as represented in CVE-2025-21176. Additionally, if you've deployed self-contained applications https://docs.microsoft.com/dotnet/core/deploying/#self-contained-deployments-scd  targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS0.72% probability of exploitation · percentile 49.0% · 2026-06-18T12:00:27Z
Published2025-09-08
Last modified2026-04-15

Underlying weaknesses· 1

CWE-126

References

  1. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21176
  2. https://www.herodevs.com/vulnerability-directory/cve-2025-21176

1

TypeTargetConfidenceTier
WeaknessBuffer Over-readcwe-1260%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-36854
CVE
CVE-2025-21176
CVE
CVE-2025-66589
CVE
CVE-2026-35433
CVE
CVE-2025-59295
CVE
Microsoft .NET Framework Remote Code Execution Vulnerability
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.