Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-24070

Опубликовано: 11 мар. 2025
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

A flaw was found in the SignInManager.RefreshSignInAsync method. This flaw allows an attacker with local access and low privileges to escalate privileges. The issue might lead to unauthorized access or manipulation of authentication sessions.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dotnet8.0Affected
Red Hat Enterprise Linux 10dotnet9.0Affected
Red Hat Enterprise Linux 9dotnet6.0Not affected
Red Hat Enterprise Linux 9dotnet7.0Not affected
Red Hat Enterprise Linux 8dotnet9.0FixedRHSA-2025:266711.03.2025
Red Hat Enterprise Linux 8dotnet8.0FixedRHSA-2025:267011.03.2025
Red Hat Enterprise Linux 9dotnet9.0FixedRHSA-2025:266811.03.2025
Red Hat Enterprise Linux 9dotnet8.0FixedRHSA-2025:266911.03.2025
Red Hat Enterprise Linux 9.4 Extended Update Supportdotnet8.0FixedRHSA-2025:266611.03.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2349733dotnet: Privilege Escalation Vulnerability in .NET SignInManager.RefreshSignInAsync Method

EPSS

Процентиль: 32%
0.00123
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
3 месяца назад

Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 7
nvd
3 месяца назад

Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 7
msrc
3 месяца назад

ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability

rocky
около 1 месяца назад

Important: .NET 8.0 security, bug fix, and enhancement update

rocky
около 1 месяца назад

Important: .NET 9.0 security, bug fix, and enhancement update

EPSS

Процентиль: 32%
0.00123
Низкий

7.8 High

CVSS3