Microsoft ASP.NET Core
cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*
A vulnerability allowing privilege escalation has been identified in ASP.NET Core. This issue arises from an incorrect implementation of the authentication algorithm, which enables an authorized attacker to elevate privileges over a network. The vulnerability affects several versions of ASP.NET Core, as well as .NET 8.0, 9.0, and 10.0 across different operating systems.
Exploitation of this vulnerability could allow an authorized attacker to gain elevated privileges, potentially leading to administrative or SYSTEM rights.
Users can download the security update for this vulnerability through the Microsoft Visual Studio Update system or via the .NET download pages for the respective versions. For Visual Studio, the update is available through the Visual Studio 2026, 2022 version 17.14, and 17.12 channels. .NET users can find the update on the official .NET download site.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.