Microsoft ASP.NET Core
cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*
A vulnerability in ASP.NET Core allows an authorized attacker to bypass authentication and elevate privileges over a network. This issue arises from an authentication bypass by assumed-immutable data, which could be exploited to gain SYSTEM privileges.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.
Users can download the security update for this vulnerability through the Microsoft Visual Studio Update system or via the Microsoft Update Catalog. For .NET users, the security update is available on the .NET download page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.