Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.832386
Category:Windows
Title:.NET Core Multiple Vulnerabilities (KB5029688, KB5029689) - Windows
Summary:.NET Core prone to security feature bypass; and elevation of privilege vulnerabilities.
Description:Summary:
.NET Core prone to security feature bypass
and elevation of privilege vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to,

- A vulnerability exists when some dotnet commands are used in
directories with weaker permissions which can result in remote code execution.

- A vulnerability exists in Kestrel where, on detecting a potentially malicious
client, Kestrel will sometimes fail to disconnect it, resulting in denial of service.

Vulnerability Impact:
Successful exploitation would allow an attacker
to bypass security restrictions, achieve cross-session/cross-user elevation of
privilege (EoP) and code execution.

Affected Software/OS:
.NET Core runtime 6.0 before 6.0.21, 7.0 before
7.0.10 and .NET Core SDK before 6.0.121, 6.0.316, 7.0.400.

Solution:
Upgrade to versions 6.0.21 or 7.0.10 or later or
upgrade .NET Core SDK to versions 6.0.121 or 6.0.316 or
7.0.400 or later.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2023-35390
.NET and Visual Studio Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35390
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CL2L4WE5QRT7WEXANYXSKSU43APC5N2V/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NWVZFKTLNMNKPZ755EMRYIA6GHFOWGKY/
Common Vulnerability Exposure (CVE) ID: CVE-2023-38180
.NET and Visual Studio Denial of Service Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38180
Common Vulnerability Exposure (CVE) ID: CVE-2023-35391
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35391
Common Vulnerability Exposure (CVE) ID: CVE-2023-38178
.NET Core and Visual Studio Denial of Service Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38178
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.