CVE-2022-34716: .NET Spoofing Vulnerability

Published Aug 4, 2022
·
Updated

.NET Spoofing Vulnerability

Other sources

Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-vh55-786g-wjwj. This link is maintained to preserve external references.

Original Description Microsoft is releasing this security advisory to provide information about a vulnerability in .NET Core 3.1 and .NET 6.0. An information disclosure vulnerability exists in .NET Core 3.1 and .NET 6.0 that could lead to unauthorized access of privileged information.

Affected software

Any .NET 6.0 application running on .NET 6.0.7 or earlier. Any .NET Core 3.1 applicaiton running on .NET Core 3.1.27 or earlier.

Patches

If you're using .NET 6.0, you should download and install Runtime 6.0.8 or SDK 6.0.108 (for Visual Studio 2022 v17.1) from https://dotnet.microsoft.com/download/dotnet-core/6.0. If you're using .NET Core 3.1, you should download and install Runtime 3.1.28 (for Visual Studio 2019 v16.9) from https://dotnet.microsoft.com/download/dotnet-core/3.1.

GitHub

An information disclosure vulnerability exists in .NET Core and .NET. This issue can lead to unauthorized access to privileged information.

External Entity Injection during XML signature verification.

Red Hat

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET Core 3.1 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An information disclosure vulnerability exists in .NET Core 3.1 and .NET 6.0 that could lead to unauthorized access of privileged information.

<a name="affected-software"></a>Affected software

Any .NET 6.0 application running on .NET 6.0.7 or earlier. Any .NET Core 3.1 applicaiton running on .NET Core 3.1.27 or earlier.

If your application uses the following package versions, ensure you update to the latest version of .NET.

<a name=".NET Core 3.1"></a>.NET Core 3.1

Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- System.Security.Cryptography.Xml| <=4.7.0| 4.7.1 Microsoft.AspNetCore.App.Runtime.win-x64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.linux-x64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.win-x86| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.osx-x64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.linux-musl-x64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.linux-arm64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.linux-arm| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.win-arm64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.win-arm| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64| >=3.1.0, 3.1.27| 3.1.28 Microsoft.AspNetCore.App.Runtime.linux-musl-arm| >=3.1.0, 3.1.27| 3.1.28

<a name=".NET 6"></a>.NET 6

Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- System.Security.Cryptography.Xml| >=5.0.0, 6.0.0| 6.0.1 Microsoft.AspNetCore.App.Runtime.win-x64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.linux-x64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.win-x86| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.osx-x64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.linux-musl-x64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.linux-arm64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.linux-arm| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.win-arm64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.win-arm| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.osx-arm64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64| >=6.0.0, 6.0.7| 6.0.8 Microsoft.AspNetCore.App.Runtime.linux-musl-arm| >=6.0.0, 6.0.7| 6.0.8

Patches

If you're using .NET 6.0, you should download and install Runtime 6.0.8 or SDK 6.0.108 (for Visual Studio 2022 v17.1) from https://dotnet.microsoft.com/download/dotnet-core/6.0. If you're using .NET Core 3.1, you should download and install Runtime 3.1.28 (for Visual Studio 2019 v16.9) from https://dotnet.microsoft.com/download/dotnet-core/3.1.

Other

Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/232 An Issue for this can be found at https://github.com/dotnet/aspnetcore/issues/43166 MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34716

GitHub

Affected Software

66 affected componentsFixes available
redhat/rh-dotnet31-dotnet<0:3.1.422-1.el7_9
0:3.1.422-1.el7_9
redhat/rh-dotnet60-dotnet<0:6.0.108-1.el7_9
0:6.0.108-1.el7_9
redhat/dotnet3.1<0:3.1.422-1.el8_6
0:3.1.422-1.el8_6
redhat/dotnet6.0<0:6.0.108-1.el8_6
0:6.0.108-1.el8_6
redhat/dotnet6.0<0:6.0.108-1.el9_0
0:6.0.108-1.el9_0
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm>=6.0.0<=6.0.7
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm>=3.1.0<=3.1.27
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64>=6.0.0<=6.0.7
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64>=3.1.0<=3.1.27
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.osx-arm64>=6.0.0<=6.0.7
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.win-arm>=6.0.0<=6.0.7
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.win-arm>=3.1.0<=3.1.27
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64>=6.0.0<=6.0.7
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64>=3.1.0<=3.1.27
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm>=6.0.0<=6.0.7
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm>=3.1.0<=3.1.27
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64>=6.0.0<=6.0.7
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64>=3.1.0<=3.1.27
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64>=6.0.0<=6.0.7
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64>=3.1.0<=3.1.27
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64>=6.0.0<=6.0.7
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64>=3.1.0<=3.1.27
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.win-x86>=6.0.0<=6.0.7
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.win-x86>=3.1.0<=3.1.27
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64>=6.0.0<=6.0.7
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64>=3.1.0<=3.1.27
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.win-x64>=6.0.0<=6.0.7
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.win-x64>=3.1.0<=3.1.27
3.1.28
nuget/System.Security.Cryptography.Xml>=5.0.0<=6.0.0
6.0.1
nuget/System.Security.Cryptography.Xml<=4.7.0
4.7.1
Microsoft .NET 6.0
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm>=6.0.0<6.0.8
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm>=3.1.0<3.1.28
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64>=6.0.0<6.0.8
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64>=3.1.0<3.1.28
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.win-arm>=6.0.0<6.0.8
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.win-arm>=3.1.0<3.1.28
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64>=6.0.0<6.0.8
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64>=3.1.0<3.1.28
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm>=6.0.0<6.0.8
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm>=3.1.0<3.1.28
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64>=6.0.0<6.0.8
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64>=3.1.0<3.1.28
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64>=6.0.0<6.0.8
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64>=3.1.0<3.1.28
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64>=6.0.0<6.0.8
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64>=3.1.0<3.1.28
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.win-x86>=6.0.0<6.0.8
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.win-x86>=3.1.0<3.1.28
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64>=6.0.0<6.0.8
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64>=3.1.0<3.1.28
3.1.28
nuget/Microsoft.AspNetCore.App.Runtime.win-x64>=6.0.0<6.0.8
6.0.8
nuget/Microsoft.AspNetCore.App.Runtime.win-x64>=3.1.0<3.1.28
3.1.28
nuget/System.Security.Cryptography.Xml>=5.0.0<6.0.1
6.0.1
nuget/System.Security.Cryptography.Xml<4.7.1
4.7.1
Microsoft PowerShell 7.0
Microsoft Visual Studio 2019 (includes 16.0 - 16.8)=16.9
Microsoft Visual Studio 2019 (includes 16.0 - 16.10)=16.11
Microsoft Visual Studio 2017 (includes 15.0 - 15.8)=15.9
Microsoft .NET Core=3.1
Microsoft .NET>=6.0.0<6.0.8
Microsoft .NET Core>=3.1<3.1.28
Microsoft PowerShell>=7.0<7.0.12
Microsoft PowerShell>=7.2<7.2.6
Microsoft Visual Studio 2022=17.2
Microsoft Visual Studio 2022=17.0

Event History

Aug 4, 2022
Data Sourced
via Red Hat·04:51 AM
DescriptionSeverityAffected Software
Aug 9, 2022
CVE Published
12:00 AM
Data Sourced
07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·07:55 PM
Data Sourced
via MITRE·07:55 PM
DescriptionSeverity
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 10, 2022
Advisory Published
via GitHub·12:00 AM
Apr 2, 2024
Withdrawn
via GitHub·07:01 PM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-34716?

CVE-2022-34716 is a .NET spoofing vulnerability that can lead to unauthorized access to privileged information.

2

What is the severity of CVE-2022-34716?

The severity of CVE-2022-34716 is high with a severity value of 5.9.

3

Which software is affected by CVE-2022-34716?

The following software is affected: .NET Core, .NET, rh-dotnet31-dotnet, rh-dotnet60-dotnet, dotnet3.1, dotnet6.0, PowerShell 7.2, Visual Studio 2017 (includes 15.0 - 15.8), Visual Studio 2019 (includes 16.0 - 16.10), Microsoft .NET Core, Microsoft .NET 6.0, Visual Studio 2019 (includes 16.0 - 16.8), Visual Studio 2022, Microsoft .NET, Microsoft .NET Core, and Microsoft PowerShell.

4

How can I fix the CVE-2022-34716 vulnerability?

Apply the available patches or updates provided by the respective vendors for the affected software.

5

Where can I find more information about CVE-2022-34716?

You can find more information about CVE-2022-34716 at the following references: [Microsoft Security Response Center](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34716), [CVE](https://www.cve.org/CVERecord?id=CVE-2022-34716), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-34716), and [GitHub](https://github.com/dotnet/announcements/issues/232).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203