Severity
7.0HIGH
EPSS
0.3%
top 45.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11

Description

Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:HExploitability: 2.2 | Impact: 4.7

Affected Packages22 packages

🔴Vulnerability Details

4
CVEList
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability2025-03-11
OSV
CVE-2025-24070: Weak authentication in ASP2025-03-11
OSV
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability2025-03-11
GHSA
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability2025-03-11

📋Vendor Advisories

4
Ubuntu
.NET vulnerability2025-03-11
Red Hat
dotnet: Privilege Escalation Vulnerability in .NET SignInManager.RefreshSignInAsync Method2025-03-11
Microsoft
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability2025-03-11
Microsoft
Apache Subversion mod_dav_svn is vulnerable to memory corruption2022-04-12