cbcvebase.
CVE-2025-24070
published 2025-03-11

CVE-2025-24070: Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

high7CVSS 3.1
AVNACHPRNUINSUCLILAH
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

Affected

57 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftasp.net_core>= 8.0.0 < 8.0.148.0.14
microsoftasp.net_core>= 9.0.0 < 9.0.39.0.3
microsoftasp.net_core_8.0>= 8.0 < 8.0.148.0.14
microsoftasp.net_core_9.0>= 9.0 < 9.0.39.0.3
microsoftmicrosoft.aspnetcore.app.runtime.linux-arm6.0.0 – 6.0.36
microsoftmicrosoft.aspnetcore.app.runtime.linux-arm>= 8.0.0 < 8.0.148.0.14
microsoftmicrosoft.aspnetcore.app.runtime.linux-arm>= 9.0.0 < 9.0.39.0.3
microsoftmicrosoft.aspnetcore.app.runtime.linux-arm646.0.0 – 6.0.36
microsoftmicrosoft.aspnetcore.app.runtime.linux-arm64>= 8.0.0 < 8.0.148.0.14
microsoftmicrosoft.aspnetcore.app.runtime.linux-arm64>= 9.0.0 < 9.0.39.0.3
microsoftmicrosoft.aspnetcore.app.runtime.linux-musl-arm6.0.0 – 6.0.36
microsoftmicrosoft.aspnetcore.app.runtime.linux-musl-arm>= 8.0.0 < 8.0.148.0.14
microsoftmicrosoft.aspnetcore.app.runtime.linux-musl-arm>= 9.0.0 < 9.0.39.0.3
microsoftmicrosoft.aspnetcore.app.runtime.linux-musl-arm646.0.0 – 6.0.36
microsoftmicrosoft.aspnetcore.app.runtime.linux-musl-arm64>= 8.0.0 < 8.0.148.0.14
microsoftmicrosoft.aspnetcore.app.runtime.linux-musl-arm64>= 9.0.0 < 9.0.39.0.3
microsoftmicrosoft.aspnetcore.app.runtime.linux-musl-x646.0.0 – 6.0.36
microsoftmicrosoft.aspnetcore.app.runtime.linux-musl-x64>= 8.0.0 < 8.0.148.0.14
microsoftmicrosoft.aspnetcore.app.runtime.linux-musl-x64>= 9.0.0 < 9.0.39.0.3
microsoftmicrosoft.aspnetcore.app.runtime.linux-x646.0.0 – 6.0.36
microsoftmicrosoft.aspnetcore.app.runtime.linux-x64>= 8.0.0 < 8.0.148.0.14
microsoftmicrosoft.aspnetcore.app.runtime.linux-x64>= 9.0.0 < 9.0.39.0.3
microsoftmicrosoft.aspnetcore.app.runtime.osx-arm646.0.0 – 6.0.36
microsoftmicrosoft.aspnetcore.app.runtime.osx-arm64>= 8.0.0 < 8.0.148.0.14
microsoftmicrosoft.aspnetcore.app.runtime.osx-arm64>= 9.0.0 < 9.0.39.0.3

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
ghsa7.0HIGH
osv7.0HIGH