CVE-2021-43877: high-severity vulnerability in Microsoft ASP.NET Core 3.1
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 0.7%
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
nono source reports it
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected products
Microsoft · ASP.NET Core 3.1Microsoft · ASP.NET Core 5.0Microsoft · ASP.NET Core 6.0Microsoft · Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)Microsoft · Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6)Microsoft · Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)Microsoft · Microsoft Visual Studio 2022 version 17.0Microsoft · Microsoft Visual Studio 2022 version 17.1Related CVEs — Microsoft ASP.NET Core 3.1
In the same product, most dangerous first.
CVE-2020-1597—ASP.NET Core Denial of Service VulnerabilityEPSS 6.6%CVE-2020-1045HIGHMicrosoft ASP.NET Core Security Feature Bypass VulnerabilityEPSS 5.9%CVE-2021-1723HIGHASP.NET Core and Visual Studio Denial of Service VulnerabilityEPSS 5.3%CVE-2020-1161—ASP.NET Core Denial of Service VulnerabilityEPSS 5.3%CVE-2024-21386HIGH.NET Denial of Service VulnerabilityEPSS 2.4%CVE-2021-34532MEDIUMASP.NET Core and Visual Studio Information Disclosure VulnerabilityEPSS 1.2%