CVE-2023-36558
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2023-36558 is a security vulnerability affecting ASP.NET Core applications. This issue allows an attacker to bypass security features, potentially gaining unauthorized access to protected resources. The vulnerability arises due to improper validation of user input in certain scenarios. Successful exploitation of this vulnerability could lead to remote code execution or information disclosure, posing a significant risk to affected systems. It is recommended that organizations using ASP.NET Core immediately apply the available security patch to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft .NET Framework
- Microsoft Visual Studio 2022
- Microsoft ASP.NET Core
Affected Vendors
- Microsoft