CVE-2018-0787
published 2018-03-14CVE-2018-0787: ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests…
PriorityP350high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
9.95%
95.1th percentile
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability".
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | — | — |
| microsoft_corporation | asp.net_core | — | — |
| msrc | asp.net_core_2.0 | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
ASP.NET Core allow an elevation of privilege
ghsa·2018-10-16
CVE-2018-0787 [HIGH] CWE-640 ASP.NET Core allow an elevation of privilege
ASP.NET Core allow an elevation of privilege
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability".
OSV
ASP.NET Core allow an elevation of privilege
osv·2018-10-16
CVE-2018-0787 [HIGH] ASP.NET Core allow an elevation of privilege
ASP.NET Core allow an elevation of privilege
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability".
Microsoft
ASP.NET Core Elevation of Privilege Vulnerability
vendor_msrc·2018-03-13·CVSS 8.8
CVE-2018-0787 [HIGH] ASP.NET Core Elevation of Privilege Vulnerability
ASP.NET Core Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when a Kestrel web application fails to validate web requests.
An attacker who successfully exploited this vulnerability could perform HTML injection attacks.
To exploit the vulnerability, an attacker could send a specially crafted request, containing injected HTML, to the web application. The specially crafted request would initiate a "password reset" email to the target user.
Depending on the target user email client, the injected HTML could trigger as soon as the target user opens the "password reset" e-mail.
The security update addresses the vulnerability by correcting how a Kestrel web application validates web requests.
ASP .NET: ASP .NET
Impact: Elevation of Privilege
Ex
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - March 2018
blogs_talos·2018-03-13·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - March 2018
### Microsoft Patch Tuesday - March 2018 Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 74 new vulnerabilities, with 14 of them rated critical and 59 of them rated important. These vulnerabilities impact Internet Explorer, Edge, Exchange, Scripting Engine, Windows Shell and more.
#### Critical Vulnerabilities This month, Microsoft is addressing 14 vulnerabilities that are rated as critical.
The vulnerabilities rated as critical are listed below:
CVE-2018-0872 - Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2018-0874 - Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2018-0876 - Scripting Engine Memory Corruption Vulnerabi
Talos
Microsoft Patch Tuesday - March 2018
blogs_talos·2018-03-13·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - March 2018
## Microsoft Patch Tuesday - March 2018
## Microsoft Patch Tuesday - March 2018 Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 74 new vulnerabilities, with 14 of them rated critical and 59 of them rated important. These vulnerabilities impact Internet Explorer, Edge, Exchange, Scripting Engine, Windows Shell and more.
## Critical Vulnerabilities This month, Microsoft is addressing 14 vulnerabilities that are rated as critical.
The vulnerabilities rated as critical are listed below:
CVE-2018-0872 - Chakra Scripting Engine Memory Corruption Vulnerability CVE-2018-0874 - Chakra Scripting Engine Memory Corruption Vulnerability CVE-2018-0876 - Script
http://www.securityfocus.com/bid/103282http://www.securitytracker.com/id/1040525https://github.com/aspnet/Announcements/issues/295https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0787http://www.securityfocus.com/bid/103282http://www.securitytracker.com/id/1040525https://github.com/aspnet/Announcements/issues/295https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0787
2018-03-14
Published