CVE-2023-36558HighCVSS 6.2

ASP.NET Core Security Feature Bypass Vulnerability

Published
November 14, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What kind of security feature could be bypassed by successfully exploiting this vulnerability? An unauthenticated attacker could bypass validations on Blazor Server forms.

How could an attacker exploit this vulnerability? To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then trigger an event that could exploit the vulnerability to save an invalid state to a database or trigger other unintended actions, depending on what functionality the form provides.

🎯 Affected products10

  • .NET 6.0
  • .NET 7.0
  • .NET 8.0
  • ASP.NET Core 6.0
  • ASP.NET Core 7.0
  • ASP.NET Core 8.0
  • Microsoft Visual Studio 2022 version 17.2
  • Microsoft Visual Studio 2022 version 17.4
  • Microsoft Visual Studio 2022 version 17.6
  • Microsoft Visual Studio 2022 version 17.7

✅ Remediation

KB5032883 (Security Update) — fixed build 6.0.25 KBRelease Notes (Security Update) — fixed build 6.0.25 KB5032884 (Security Update) — fixed build 7.0.14 KBRelease Notes (Security Update) — fixed build 17.2.22 KBRelease Notes (Security Update) — fixed build 8.0.0 KBRelease Notes (Security Update) — fixed build 17.4.14 KBRelease Notes (Security Update) — fixed build 17.6.10 KBRelease Notes (Security Update) — fixed build 17.7.7 KBRelease Notes (Security Update) — fixed build 7.0.14

🔗 References (16)