Описание
ASP.NET Core Elevation of Privilege Vulnerability
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
FAQ
What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain administrator privileges.
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| .NET 8.0 installed on Windows | ||
| .NET 8.0 installed on Linux | ||
| .NET 8.0 installed on Mac OS | ||
| .NET 9.0 installed on Linux | ||
| .NET 9.0 installed on Mac OS | ||
| .NET 9.0 installed on Windows | ||
| Microsoft Visual Studio 2022 version 17.12 | ||
| Microsoft Visual Studio 2022 version 17.14 | ||
| .NET 10.0 installed on Mac OS | ||
| .NET 10.0 installed on Linux |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
8.8 High
CVSS3
Связанные уязвимости
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Microsoft Security Advisory CVE-2026-47300 – .NET Elevation of Privilege Vulnerability
ELSA-2026-41897: .NET 10.0 security, bug fix, and enhancement update (IMPORTANT)
EPSS
8.8 High
CVSS3