QID 91756

Date Published: 2021-04-12

QID 91756: Microsoft .NET Core Security Update March 2021

A denial of service vulnerability exists when .NET Core improperly handles web requests.
This security update is rated Important for supported versions of .NET Core.

Affected versions:
Any .NET Core 2.1 , 3.1 or .NET 5.0 application running on .NET Core 2.1.25, 3.1.12 or .NET 5.0.3 or lower respectively.

QID Detection Logic (Authenticated):
The qid looks for sub directories under %programfiles%\dotnet\shared\Microsoft.NETCore.App, %programfiles(x86)%\dotnet\shared\Microsoft.NETCore.App and checks for vulnerable versions in .version file on Windows.

Successful exploitation allows attacker to bypass the security feature and allows set a second cookie with the name being percent encoded.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to CVE-2021-26701 for more details pertaining to this vulnerability.

    CVEs related to QID 91756

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-26701 WIndows URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26701