CVE-2022-34716: .NET Spoofing Vulnerability
.NET Spoofing Vulnerability
Other sources
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-vh55-786g-wjwj. This link is maintained to preserve external references.
Original Description Microsoft is releasing this security advisory to provide information about a vulnerability in .NET Core 3.1 and .NET 6.0. An information disclosure vulnerability exists in .NET Core 3.1 and .NET 6.0 that could lead to unauthorized access of privileged information.
Affected software
Any .NET 6.0 application running on .NET 6.0.7 or earlier. Any .NET Core 3.1 applicaiton running on .NET Core 3.1.27 or earlier.
Patches
If you're using .NET 6.0, you should download and install Runtime 6.0.8 or SDK 6.0.108 (for Visual Studio 2022 v17.1) from https://dotnet.microsoft.com/download/dotnet-core/6.0. If you're using .NET Core 3.1, you should download and install Runtime 3.1.28 (for Visual Studio 2019 v16.9) from https://dotnet.microsoft.com/download/dotnet-core/3.1.
— GitHub
An information disclosure vulnerability exists in .NET Core and .NET. This issue can lead to unauthorized access to privileged information.
External Entity Injection during XML signature verification.
— Red Hat
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET Core 3.1 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An information disclosure vulnerability exists in .NET Core 3.1 and .NET 6.0 that could lead to unauthorized access of privileged information.
<a name="affected-software"></a>Affected software
Any .NET 6.0 application running on .NET 6.0.7 or earlier. Any .NET Core 3.1 applicaiton running on .NET Core 3.1.27 or earlier.
If your application uses the following package versions, ensure you update to the latest version of .NET.
<a name=".NET Core 3.1"></a>.NET Core 3.1
Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- System.Security.Cryptography.Xml| <=4.7.0| 4.7.1 Microsoft.AspNetCore.App.Runtime.win-x64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.linux-x64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.win-x86| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.osx-x64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.linux-musl-x64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.linux-arm64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.linux-arm| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.win-arm64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.win-arm| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.linux-musl-arm| >=3.1.0, 3.1.27| 3.1.28
<a name=".NET 6"></a>.NET 6
Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- System.Security.Cryptography.Xml| >=5.0.0, 6.0.0| 6.0.1 Microsoft.AspNetCore.App.Runtime.win-x64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.linux-x64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.win-x86| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.osx-x64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.linux-musl-x64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.linux-arm64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.linux-arm| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.win-arm64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.win-arm| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.osx-arm64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.linux-musl-arm| >=6.0.0, 6.0.7| 6.0.8
Patches
If you're using .NET 6.0, you should download and install Runtime 6.0.8 or SDK 6.0.108 (for Visual Studio 2022 v17.1) from https://dotnet.microsoft.com/download/dotnet-core/6.0. If you're using .NET Core 3.1, you should download and install Runtime 3.1.28 (for Visual Studio 2019 v16.9) from https://dotnet.microsoft.com/download/dotnet-core/3.1.
Other
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/232 An Issue for this can be found at https://github.com/dotnet/aspnetcore/issues/43166 MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34716
— GitHub
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-34716?
CVE-2022-34716 is a .NET spoofing vulnerability that can lead to unauthorized access to privileged information.
What is the severity of CVE-2022-34716?
The severity of CVE-2022-34716 is high with a severity value of 5.9.
Which software is affected by CVE-2022-34716?
The following software is affected: .NET Core, .NET, rh-dotnet31-dotnet, rh-dotnet60-dotnet, dotnet3.1, dotnet6.0, PowerShell 7.2, Visual Studio 2017 (includes 15.0 - 15.8), Visual Studio 2019 (includes 16.0 - 16.10), Microsoft .NET Core, Microsoft .NET 6.0, Visual Studio 2019 (includes 16.0 - 16.8), Visual Studio 2022, Microsoft .NET, Microsoft .NET Core, and Microsoft PowerShell.
How can I fix the CVE-2022-34716 vulnerability?
Apply the available patches or updates provided by the respective vendors for the affected software.
Where can I find more information about CVE-2022-34716?
You can find more information about CVE-2022-34716 at the following references: [Microsoft Security Response Center](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34716), [CVE](https://www.cve.org/CVERecord?id=CVE-2022-34716), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-34716), and [GitHub](https://github.com/dotnet/announcements/issues/232).