Back
Microsoft Corporation
Patches for ASP.NET Core Runtime 8.0-x86
Windows
15 patches available
The ASP.NET Core Runtime enables you to run existing web/server applications.
ASP.NET Core Runtime 8.0-x86 Version 8.0.30.26373
Release Date
8/11/2026
Bug Fix?
Yes
Minor Release?
No
Patch Notes
Refer - https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.30/8.0.30.md
ASP.NET Core Runtime 8.0-x86 Version 8.0.29.26325
Release Date
7/14/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes
Refer - https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.29/8.0.129.md
ASP.NET Core Runtime 8.0-x86 Version 8.0.15.25165
Release Date
4/8/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes
Refer - https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.15/8.0.15.md
ASP.NET Core Runtime 8.0-x86 Version 8.0.14.25112
Release Date
3/11/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes
Refer - https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.14.md?WT.mc_id=dotnet-35129-website#net-8014---march-11-2025
ASP.NET Core Runtime 8.0-x86 Version 8.0.13.25066
Release Date
2/11/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes
Refer - https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.13/8.0.13.md#net-8013---february-11-2025
ASP.NET Core Runtime 8.0-x86 Version 8.0.12.24603
Release Date
1/14/2025
Bug Fix?
Yes
Minor Release?
No
Patch Notes
Notable Changes$$$.NET 8.0.12 release carries the security fixes and non-security fixes.$$$$$$Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$An attacker could exploit this vulnerability by loading a specially crafted file in Visual Studio.$$$$$$Microsoft Security Advisory CVE-2025-21173 | .NET Elevation of Privilege Vulnerability$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$An attacker could exploit this vulnerability to writing a specially crafted file in the security context of the local system. This only affects .NET on Linux operating systems.$$$$$$Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$An attacker could exploit this vulnerability by loading a specially crafted file in Visual Studio.$$$$$$Visual Studio Compatibility$$$You need Visual Studio 17.12 or later to use .NET 8.0 on Windows. While not officially supported; we’ve also enabled rudimentary support for .NET 8 in Visual Studio for Mac. Users have to enable a preview feature in Preferences to enable the IDE to discover and use the .NET 8 SDK for creating; loading; building; and debugging projects. The C# extension for Visual Studio Code supports .NET 8.0 and C# 12.
ASP.NET Core Runtime 8.0-x86 Version 8.0.11.24521
Release Date
11/12/2024
Bug Fix?
No
Minor Release?
Yes
Patch Notes
Notable Changes$$$This update contains non-security changes$$$$$$Visual Studio Compatibility$$$You need Visual Studio 17.11 or later to use .NET 8.0 on Windows. While not officially supported; we’ve also enabled rudimentary support for .NET 8 in Visual Studio for Mac. Users have to enable a preview feature in Preferences to enable the IDE to discover and use the .NET 8 SDK for creating; loading; building; and debugging projects. The C# extension for Visual Studio Code supports .NET 8.0 and C# 12.
ASP.NET Core Runtime 8.0-x86 Version 8.0.10.24468
Release Date
10/8/2024
Bug Fix?
No
Minor Release?
Yes
Patch Notes
.NET 8.0.10 release carries the security fixes and non-security fixes.$$$$$$Microsoft Security Advisory CVE-2024-38229 | .NET Remote Code Execution Vulnerability$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$A vulnerability exists in ASP.NET when closing an HTTP/3 stream while application code is writing to the response body; a race condition may lead to use-after-free.$$$$$$Note: HTTP/3 is experimental in .NET 6.0. If you are on .NET 6.0 and using HTTP/3; please upgrade to .NET 8.0.10. .NET 6.0 will not receive a security patch for this vulnerability.
ASP.NET Core Runtime 8.0-x86 Version 8.0.8.24369
Release Date
8/13/2024
Bug Fix?
No
Minor Release?
Yes
Patch Notes
.NET 8.0.8 - August 13; 2024$$$The .NET 8.0.8 and .NET SDK 8.0.400 releases are available for download. The latest 8.0 release is always listed at .NET 8.0 Releases.$$$$$$Downloads$$$SDK Installer1tSDK Binaries1tRuntime InstallertRuntime BinariestASP.NET Core RuntimetWindows Desktop Runtime$$$Windowstx86 | x64 | Arm64tx86 | x64 | Arm64tx86 | x64 | Arm64tx86 | x64 | Arm64tx86 | x64 |$$$Hosting Bundle2tx86 | x64 | Arm64$$$macOStx64 | ARM64tx64 | ARM64tx64 | ARM64tx64 | ARM64tx64 | ARM64t-$$$LinuxtSnap and Package Managertx64 | Arm | Arm64 | Arm32 Alpine | x64 AlpinetPackages (x64)tx64 | Arm | Arm64 | Arm32 Alpine | Arm64 Alpine | x64 Alpinetx641 | Arm1 | Arm641 | x64 Alpinet-$$$ChecksumstChecksumstChecksumstChecksumstChecksumstChecksums$$$Includes the .NET Runtime and ASP.NET Core Runtime$$$For hosting stand-alone apps on Windows Servers. Includes the ASP.NET Core Module for IIS and can be installed separately on servers without installing .NET Runtime.$$$The .NET SDK includes a matching updated .NET Runtime. Downloading the Runtime or ASP.NET Core packages is not needed when installing the SDK.$$$$$$You can check your .NET SDK version by running the following command. The example version shown is for this release.$$$$$$$ dotnet --version$$$8.0.400$$$Docker Images$$$The .NET Docker images have been updated for this release. The .NET Docker samples show various ways to use .NET and Docker together. You can use the following command to try running the latest .NET 8.0 release in containers:$$$$$$docker run --rm mcr.microsoft.com/dotnet/samples$$$The following repos have been updated.$$$$$$dotnet/sdk: .NET SDK$$$dotnet/aspnet: ASP.NET Core Runtime$$$dotnet/runtime: .NET Runtime$$$dotnet/runtime-deps: .NET Runtime Dependencies$$$dotnet/monitor: .NET Monitor$$$dotnet/monitor/base: .NET Monitor Base$$$dotnet/aspire-dashboard: .NET Aspire Dashboard$$$dotnet/samples: .NET Samples$$$Notable Changes$$$.NET 8.0 Blog$$$$$$.NET 8.0.8 release carries the security fixes and non-security fixes.$$$$$$CVE-2024-38168 | .NET Denial of Service Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$A vulnerability exists in .NET when an attacker through unauthenticated requests may trigger a Denial of Service in ASP.NET HTTP.sys web server. This is a windows OS only vulnerability.$$$$$$CVE-2024-38167 | .NET Information Disclosure Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$A vulnerability exists in .NET runtime TlsStream which may result in Information Disclosure.$$$$$$Visual Studio Compatibility$$$You need Visual Studio 17.11 or later to use .NET 8.0 on Windows. While not officially supported; we’ve also enabled rudimentary support for .NET 8 in Visual Studio for Mac. Users have to enable a preview feature in Preferences to enable the IDE to discover and use the .NET 8 SDK for creating; loading; building; and debugging projects. The C# extension for Visual Studio Code supports .NET 8.0 and C# 12.
ASP.NET Core Runtime 8.0-x86 Version 8.0.7.24314
Release Date
7/9/2024
Bug Fix?
No
Minor Release?
Yes
Patch Notes
Notable Changes$$$.NET 8.0 Blog$$$$$$.NET 8.0.7 release carries the security fixes and non-security fixes.$$$$$$CVE-2024-38095 | .NET Denial of Service Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0 and .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$A Vulnerability exists when System.Formats.Asn1 in .NET parses an X.509 certificate or collection of certificates; a malicious certificate can result in excessive CPU consumption on all platforms result in Denial of Service.$$$$$$CVE-2024-35264 | .NET Remote Code Execution Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$A Vulnerability exists in ASP.NET Core 8 where Data Corruption in Kestrel HTTP/3 can result in remote code execution.$$$$$$Note: HTTP/3 is experimental in .NET 6.0. If you are on .NET 6.0 and using HTTP/3; please upgrade to .NET 8.0.7$$$$$$CVE-2024-30105 | .NET Denial of Service Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$A vulnerability exists in .NET when calling the JsonSerializer.DeserializeAsyncEnumerable method against an untrusted input using System.Text.Json may result in Denial of Service.
ASP.NET Core Runtime 8.0-x86 Version 8.0.6.24269
Release Date
5/19/2024
Bug Fix?
No
Minor Release?
Yes
Patch Notes
Notable Changes$$$.NET 8.0 Blog$$$$$$.NET 8.0.6 release carries the security fixes and non-security fixes.$$$$$$WiX toolset signed with incorrect certificate$$$The .NET 8.0.5 release on May 14; 2024 included updates to the WiX toolset which were incorrectly signed. This caused failures in scenarios on Windows where Code Integrity checks were enabled.$$$$$$CVE-2024-20672 | .NET Denial of Service Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0; .NET 7.0 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$A vulnerability exists in .NET when processing X.509 certificates that may result in Denial of Service. This vulnerabilty only affects macOS.
ASP.NET Core Runtime 8.0-x86 Version 8.0.5.24224
Release Date
5/14/2024
Bug Fix?
No
Minor Release?
Yes
Patch Notes
Notable Changes$$$.NET 8.0 Blog$$$$$$.NET 8.0.5 release carries security and non-security fixes.$$$$$$CVE-2024-30045 | .NET Remote Code Execution Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$A Remote Code Execution vulnerability exists in .NET 7.0 and .NET 8.0 where a stack buffer overrun occurs in .NET Double Parse routine.$$$$$$CVE-2024-30046 | .NET Denial of Service Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$A Vulnerability exist in Microsoft.AspNetCore.Server.Kestrel.Core.dll where a dead-lock can occur resulting in Denial of Service.
ASP.NET Core Runtime 8.0-x86 Version 8.0.4.24170
Release Date
4/9/2024
Bug Fix?
No
Minor Release?
No
Patch Notes
Notable Changes$$$.NET 8.0 Blog$$$$$$.NET 8.0.4 release carries security and non-security fixes.$$$$$$CVE-2024-21409 | .NET Elevation of Privilege Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0; .NET 7.0 ;and .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$A use-after-free vulnerability exists in WPF which may result in Elevation of Privilege when viewing untrusted documents.
ASP.NET Core Runtime 8.0-x86 Version 8.0.3.24116
Release Date
3/12/2024
Bug Fix?
No
Minor Release?
No
Patch Notes
Notable Changes$$$.NET 8.0 Blog$$$$$$.NET 8.0.3 release carries security and non-security fixes.$$$$$$CVE-2024-21392 | .NET Denial of Service Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 8.0 . This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.$$$$$$A vulnerability exists in .NET where specially crafted requests may cause a resource leak; leading to a Denial of Service$$$$$$CVE-2024-26190 | Microsoft QUIC Denial of Service Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$A Vulnerability exist in MsQuic.dll which might result in a peer to allocate small chunks of memory as long as connection stays alive.
ASP.NET Core Runtime 8.0-x86 Version 8.0.2.24068
Release Date
2/13/2024
Bug Fix?
No
Minor Release?
No
Patch Notes
Notable Changes$$$.NET 8.0 Blog$$$$$$.NET 8.0.2 release carries security and non-security fixes.$$$$$$CVE-2024-21386 | .NET Denial of Service Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET 6.0; ASP.NET 7.0 and; ASP.NET 8.0. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.$$$$$$A vulnerability exists in ASP.NET applications using SignalR where a malicious client can result in a denial-of-service.$$$$$$CVE-2024-21404 | .NET Denial of Service Vulnerability$$$$$$Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0; .NET 7.0 and .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.$$$$$$A denial-of-service vulnerability exists in .NET with OpenSSL support when parsing X509 certificates.
Interested in automating patching for ASP.NET Core Runtime 8.0-x86?