ASP.NET Core Elevation of Privilege Vulnerability
33Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.1epss 11%
exploitation probability
11%top 4% of all CVEs
observed exploitation
nono source reports it
In short
ASP.NET Core doesn't properly verify digital signatures, allowing attackers to forge authentication credentials and gain unauthorized access to systems over the network.
Technical detail
The vulnerability stems from improper cryptographic signature verification in ASP.NET Core's authentication mechanism (CWE-347), enabling remote attackers to bypass signature validation and escalate privileges without prior authentication. This affects network-accessible ASP.NET Core applications and could lead to complete system compromise.
Summary generated and translated by AI from the official description.
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C