PT-2025-10815 · Microsoft+8 · Visual Studio+9

Zahid

·

Published

2025-03-11

·

Updated

2025-12-16

·

CVE-2025-24070

CVSS v3.1

7.0

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions: ASP.NET Core versions prior to 9.0.3 ASP.NET Core versions prior to 8.0.14 ASP.NET Core versions prior to 6.0.37
Description: A vulnerability exists in ASP.NET Core applications calling RefreshSignInAsync with an improperly authenticated user parameter that could allow an attacker to sign into another user's account, resulting in Elevation of Privilege. The vulnerability is caused by weak authentication in ASP.NET Core and Visual Studio. An attacker could possibly use this issue to elevate privileges, execute arbitrary code, or cause a denial of service.
Recommendations: For ASP.NET Core version 9.0, update to .NET 9.0.3 Runtime or .NET 9.0.103 SDK. For ASP.NET Core version 8.0, update to .NET 8.0.14 Runtime. For ASP.NET Core version 6.0, update to .NET 6.0.37 Runtime. If your application references the vulnerable package, update the package reference to the patched version. Restart your apps for the update to take effect. If you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:2667
ALSA-2025:2668
ALSA-2025:2669
ALSA-2025:2670
ALT-PU-2025-13072
ALT-PU-2025-13074
ALT-PU-2025-13673
ALT-PU-2025-13674
ALT-PU-2025-15796
ALT-PU-2025-15797
BDU:2025-04300
BIT-ASPNET-CORE-2025-24070
CESA-2025_2667
CESA-2025_2670
CVE-2025-24070
GHSA-2865-HH9G-W894
INFSA-2025_2667
INFSA-2025_2668
INFSA-2025_2669
INFSA-2025_2670
RHSA-2025:2666
RHSA-2025:2667
RHSA-2025:2668
RHSA-2025:2669
RHSA-2025:2670
RHSA-2025_2667
RHSA-2025_2668
RHSA-2025_2669
RHSA-2025_2670
USN-7345-1

Affected Products

Alt Linux
Asp.Net Core
Almalinux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu
Visual Studio