Microsoft ASP.NET Core Elevation of Privilege Vulnerability

Vulnerability

A vulnerability allowing privilege escalation has been identified in ASP.NET Core. This issue arises from an incorrect implementation of the authentication algorithm, which enables an authorized attacker to elevate privileges over a network. The vulnerability affects several versions of ASP.NET Core, as well as .NET 8.0, 9.0, and 10.0 across different operating systems.

Impact

Exploitation of this vulnerability could allow an authorized attacker to gain elevated privileges, potentially leading to administrative or SYSTEM rights.

Remediation

Users can download the security update for this vulnerability through the Microsoft Visual Studio Update system or via the .NET download pages for the respective versions. For Visual Studio, the update is available through the Visual Studio 2026, 2022 version 17.14, and 17.12 channels. .NET users can find the update on the official .NET download site.

Added: Jul 15, 2026, 5:56 AM
Updated: Jul 15, 2026, 5:56 AM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
0.6
exploitability
5.4
remediation
7.7
relevance
9.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.