← back
CVE-2025-24070highCWE-1390

ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7epss 1.0%
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
In short

ASP.NET Core and Visual Studio have weak authentication that allows an attacker to gain higher privileges over a network without proper authorization. This can let someone access or control things they shouldn't be able to.

Technical detail

A weak authentication mechanism in ASP.NET Core and Visual Studio allows network-based privilege escalation by an unauthorized attacker. The vulnerability permits an unauthenticated or low-privileged user to elevate their access level remotely, potentially compromising application integrity and confidentiality depending on the affected component's role.

Summary generated and translated by AI from the official description.
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C