ASP.NET Elevation of Privilege Vulnerability: A Potential Threat to Web Applications
CVE-2023-36899
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 8 August 2023
Badges
Summary
The ASP.NET elevation of privilege vulnerability affects multiple versions of the ASP.NET framework, allowing attackers to elevate their permissions and execute unauthorized actions within the application. Proper fixes and timely updates are crucial for mitigating potential threats and securing applications against exploitation.
Affected Version(s)
Microsoft .NET Framework 2.0 Service Pack 2 Windows Server 2008 for x64-based Systems Service Pack 2 2.0.0 < 2.0.50727.8974
Microsoft .NET Framework 3.5 and 4.6.2 Windows 10 for x64-based Systems 4.7.0 < 10.0.10240.20107
Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Windows 10 Version 1607 for x64-based Systems 3.0.0.0 < 10.0.14393.6167
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved