CVE-2025-24070
published 2025-03-11CVE-2025-24070: Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
PriorityP342high7CVSS 3.1
AVNACHPRNUINSUCLILAH
EPSS
0.91%
56.0th percentile
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | >= 8.0.0 < 8.0.14 | 8.0.14 |
| microsoft | asp.net_core | >= 9.0.0 < 9.0.3 | 9.0.3 |
| microsoft | asp.net_core_8.0 | >= 8.0 < 8.0.14 | 8.0.14 |
| microsoft | asp.net_core_9.0 | >= 9.0 < 9.0.3 | 9.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | 6.0.0 – 6.0.36 | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 8.0.0 < 8.0.14 | 8.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 9.0.0 < 9.0.3 | 9.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | 6.0.0 – 6.0.36 | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 8.0.0 < 8.0.14 | 8.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 9.0.0 < 9.0.3 | 9.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | 6.0.0 – 6.0.36 | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 8.0.0 < 8.0.14 | 8.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 9.0.0 < 9.0.3 | 9.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | 6.0.0 – 6.0.36 | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 8.0.0 < 8.0.14 | 8.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 9.0.0 < 9.0.3 | 9.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | 6.0.0 – 6.0.36 | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 8.0.0 < 8.0.14 | 8.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 9.0.0 < 9.0.3 | 9.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | 6.0.0 – 6.0.36 | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 8.0.0 < 8.0.14 | 8.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 9.0.0 < 9.0.3 | 9.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | 6.0.0 – 6.0.36 | — |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 8.0.0 < 8.0.14 | 8.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 9.0.0 < 9.0.3 | 9.0.3 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
ghsa7.0HIGH
osv7.0HIGH
vendor_msrc7.5HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
.NET vulnerability
vendor_ubuntu·2025-03-11
CVE-2025-24070 .NET vulnerability
Title: .NET vulnerability
Summary: .NET could be made to elevate privileges.
Zahid TOKAT discovered that .NET suffered from a weak authentication
vulnerability. An attacker could possibly use this issue to elevate
privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dotnet: Privilege Escalation Vulnerability in .NET SignInManager.RefreshSignInAsync Method
vendor_redhat·2025-03-11·CVSS 7.0
CVE-2025-24070 [HIGH] CWE-269 dotnet: Privilege Escalation Vulnerability in .NET SignInManager.RefreshSignInAsync Method
dotnet: Privilege Escalation Vulnerability in .NET SignInManager.RefreshSignInAsync Method
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
A flaw was found in the SignInManager.RefreshSignInAsync method. This flaw allows an attacker with local access and low privileges to escalate privileges. The issue might lead to unauthorized access or manipulation of authentication sessions.
Statement: ```
.NET 6.0 for RHEL-8, RHEL-9 and RHIVOS has reached its End of Life as of November 12, 2024, and is no longer supported. No fixes will be provided for this stream. For additional information about lifecycle for .NET on Red Hat Enterprise Linux, please refer to: https://access.redhat.com/support/policy/updates/net-core.
```
M
Microsoft
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
vendor_msrc·2025-03-11·CVSS 7.0
CVE-2025-24070 [HIGH] CWE-1390 ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
Description: Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain the privileges of the compromised user.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment and take additional actions prior to exploitation to prepare the target environment.
ASP.NET Core & Visual Studio: ASP.NET Core & Visual Studio
Microso
Microsoft
Apache Subversion mod_dav_svn is vulnerable to memory corruption
vendor_msrc·2022-04-12·CVSS 7.5
CVE-2022-24070 [HIGH] CWE-416 Apache Subversion mod_dav_svn is vulnerable to memory corruption
Apache Subversion mod_dav_svn is vulnerable to memory corruption
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: ht
OSV
CVE-2025-24070: Weak authentication in ASP
osv·2025-03-11·CVSS 7.0
CVE-2025-24070 [HIGH] CVE-2025-24070: Weak authentication in ASP
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
OSV
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
osv·2025-03-11·CVSS 7.0
CVE-2025-24070 [HIGH] Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
# Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 9.0, ASP.NET Core 8.0, ASP.NET Core 6.0, and ASP.NET Core 2.3. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.
A vulnerability exists in ASP.NET Core applications calling RefreshSignInAsync with an improperly authenticated user parameter that could allow an attacker to sign into another user's account, resulting in Elevation of Privilege.
## Announcement
Announcement for this issue can be found at https://github.c
GHSA
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
ghsa·2025-03-11·CVSS 7.0
CVE-2025-24070 [HIGH] CWE-1390 Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
# Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 9.0, ASP.NET Core 8.0, ASP.NET Core 6.0, and ASP.NET Core 2.3. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.
A vulnerability exists in ASP.NET Core applications calling RefreshSignInAsync with an improperly authenticated user parameter that could allow an attacker to sign into another user's account, resulting in Elevation of Privilege.
## Announcement
Announcement for this issue can be found at https://github.c
No detection rules found.
No public exploits indexed.
2025-03-11
Published