First published: Tue Mar 04 2025(Updated: )
This vulnerability in SignInManager.RefreshSignInAsync poses a risk of privilege escalation. It allows a locally authenticated user with low privileges to potentially elevate access due to improper handling of authentication refresh mechanisms. Affected versions: .NET 8.0 .NET 9.0 Affected packages: Package(s): Microsoft.AspNetCore.App.Runtime.* Affected version: >=9.0.0, <= 9.0.2 , >=8.0.0, <=8.0.13 Patched version: 9.0.2, 8.0.14 Package(s): Microsoft.AspNetCore.Identity Affected version: 2.3.0 Patched version: 2.3.1
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET Framework | >=8.0.0<=8.0.13>=9.0.0<=9.0.2 | |
Microsoft ASP.NET Core Identity |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2349733 is classified as high due to the potential for privilege escalation.
To fix REDHAT-BUG-2349733, you should update to the latest security patches for .NET 8.0 or 9.0.
The affected versions for REDHAT-BUG-2349733 include .NET 8.0 (up to 8.0.13) and .NET 9.0 (up to 9.0.2).
Locally authenticated users with low privileges are affected by REDHAT-BUG-2349733, as it allows potential elevation of access.
REDHAT-BUG-2349733 impacts the Microsoft .NET Framework and ASP.NET Core Identity components.