Description
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
E
Unchanged
RL
O
RC
Changed
Affected products
- microsoft / Microsoft Visual Studio 2022 version 17.1217.12.0 – 17.12.22
- microsoft / Microsoft Visual Studio 2022 version 17.1417.14.0 – 17.14.36
- microsoft / Microsoft Visual Studio 2026 version 18.718.0 – 18.7.4
- microsoft / .net8.0.0 – 8.0.29
- microsoft / .NET 10.010.0.0 – 10.0.6
- microsoft / .NET 10.010.0.0 – 10.0.10
- microsoft / .NET 8.08.0.0 – 8.0.29
- microsoft / .NET 9.09.0.0 – 9.0.18
- microsoft / visual_studio_202217.12.0 – 17.12.22
- microsoft / visual_studio_202618.7.0 – 18.7.4
References
Updated 12m ago · 8 sources