QID 91844
Date Published: 2021-12-15
QID 91844: Microsoft ASP.NET Core Security Update for December 2021
An Elevation of Privilege Vulnerability exists in ASP .NET Core
This security update is rated Important for supported versions of ASP.NET Core.
Affected versions:
ASP.NET Core 3.1 prior to version 3.1.22
ASP.NET Core 5.0 prior to version 5.0.13
and ASP.NET Core 6.0 prior to version 6.0.1
QID Detection Logic (Authenticated):
This QID looks for sub directories under %programfiles%\dotnet\shared\Microsoft.NETCore.App, %programfiles(x86)%\dotnet\shared\Microsoft.NETCore.App and checks for vulnerable versions in .version file on Windows.
Successful exploitation will lead to Elevation of Privilege Vulnerability.
Solution
Customers are advised to refer to CVE-2021-43877 for more information pertaining to this vulnerability.
Vendor References
- CVE-2021-43877 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43877
CVEs related to QID 91844
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-43877 |
|