QID 91807
Date Published: 2021-08-11
QID 91807: Microsoft .NET Core and ASP.NET Core Security Update for August 2021
A denial of service vulnerability exists in .NET Core and Information Disclosure Vulnerability exists in both .NET Core and ASP .NET Core
This security update is rated Important for supported versions of .NET Core.
Affected versions:
.NET Core 2.1 before version 2.1.29
.NET Core 3.1 before version 3.1.18
.NET 5.0 before version 5.0.9
ASP.NET Core 2.1 before version 2.1.29
ASP.NET Core 3.1 before version 3.1.18
ASP.NET Core 5.0 before version 5.0.9
QID Detection Logic (Authenticated):
The qid looks for sub directories under %programfiles%\dotnet\shared\Microsoft.NETCore.App, %programfiles(x86)%\dotnet\shared\Microsoft.NETCore.App and checks for vulnerable versions in .version file on Windows.
Successful exploitation will lead to Denial of Service and Information Disclosure Vulnerability.
- CVE-2021-26423 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26423 - CVE-2021-34485 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-34485 - CVE-2021-34532 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34532
CVEs related to QID 91807
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-26423 | Windows |
|
|
| CVE-2021-34485 | Windows |
|
|
| CVE-2021-34532 | Windows |
|