CVE-2023-36558 is a security feature bypass vulnerability affecting Microsoft ASP.NET Core and Visual Studio 2022, allowing an authenticated local attacker to gain unauthorized access to sensitive information. With a CVSS score of 5.5 (Medium), this vulnerability requires local access and low privileges, but could lead to high confidentiality impact without affecting integrity or availability. While Microsoft has patched this flaw, there is currently no public exploit code available, it is not listed in CISA's KEV catalog, and community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, < 6.0.25CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.14CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
8.0.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:8.0.0:rc1:*:*:*:*:*:* | ||
8.0.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:8.0.0:rc2:*:*:*:*:*:* | ||
>= 6.0.0, < 6.0.25CPE matchmatch criteria | cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Microsoft Security Advisory CVE-2023-36558: .NET Security Feature Bypass Vulnerability
Nov 14, 2023ASP.NET Core Security Feature Bypass Vulnerability
Nov 14, 2023dotnet: ASP.NET Security Feature Bypass Vulnerability in Blazor forms
Nov 14, 2023