Описание
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
A flaw was found in ASP.NET Core due to improper verification of cryptographic signatures. An unauthorized attacker can exploit this vulnerability remotely over a network, leading to privilege escalation.
Отчет
No Red Hat products are affected as this vulnerability is specific to Microsoft.AspNetCore.DataProtection 10.0.6 from NuGet.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet10.0 | Not affected | ||
| Red Hat Hardened Images | dotnet10.0 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
9.1 Critical
CVSS3
Связанные уязвимости
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
Уязвимость программной платформы ASP.NET Core, связанная с ошибками проверки криптографической подписи, позволяющая нарушителю повысить свои привилегии
EPSS
9.1 Critical
CVSS3