‘Highest Ever’ Severity Score Assigned by Microsoft to ASP.NET Core Vulnerability

Post Reply
Shane1145
Posts: 1729
Joined: Wed Sep 25, 2024 2:31 pm

‘Highest Ever’ Severity Score Assigned by Microsoft to ASP.NET Core Vulnerability

Post by Shane1145 »

Microsoft’s October Patch Tuesday updates addressed a critical-severity vulnerability in the ASP.NET Core open source web development framework.

Tracked as CVE-2025-55315, the flaw has a CVSS score of 9.9, which .NET security program manager Barry Dorrans says was the “highest ever” for an ASP.NET Core issue.

The issue is described as an HTTP request smuggling bug that could be used to bypass a security feature over the network. It was discovered in Kestrel, ASP.NET Core’s built-in web server.

https://www.securityweek.com/highest-ev ... erability/
Post Reply