QID 91844

Date Published: 2021-12-15

QID 91844: Microsoft ASP.NET Core Security Update for December 2021

An Elevation of Privilege Vulnerability exists in ASP .NET Core
This security update is rated Important for supported versions of ASP.NET Core.

Affected versions:
ASP.NET Core 3.1 prior to version 3.1.22
ASP.NET Core 5.0 prior to version 5.0.13
and ASP.NET Core 6.0 prior to version 6.0.1

QID Detection Logic (Authenticated):
This QID looks for sub directories under %programfiles%\dotnet\shared\Microsoft.NETCore.App, %programfiles(x86)%\dotnet\shared\Microsoft.NETCore.App and checks for vulnerable versions in .version file on Windows.

Successful exploitation will lead to Elevation of Privilege Vulnerability.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are advised to refer to CVE-2021-43877 for more information pertaining to this vulnerability.

    CVEs related to QID 91844

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-43877 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43877