CVE-2018-0784: High severity asp.net core vulnerability
Published Jan 10, 2018
·Updated
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0808.
Affected Software
1 affected component
Microsoft ASP.NET Core=2.0
Remediation
Event History
Jan 10, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-0784?
CVE-2018-0784 is an elevation of privilege vulnerability in ASP.NET Core 1.0, 1.1, and 2.0.
2
What is the severity of CVE-2018-0784?
CVE-2018-0784 has a severity score of 8.8 (high).
3
How does CVE-2018-0784 affect ASP.NET Core?
CVE-2018-0784 affects ASP.NET Core versions 1.0, 1.1, and 2.0.
4
Is there a fix available for CVE-2018-0784?
Yes, Microsoft has released fixes for CVE-2018-0784. It is recommended to update to the latest version of ASP.NET Core.
5
Where can I find more information about CVE-2018-0784?
You can find more information about CVE-2018-0784 on the following websites: SecurityFocus (http://www.securityfocus.com/bid/102377) and SecurityTracker (http://www.securitytracker.com/id/1040151).