ID

VAR-202503-2006


CVE

CVE-2025-24070


DESCRIPTION

Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

Trust: 1.0

sources: NVD: CVE-2025-24070

AFFECTED PRODUCTS

vendor:microsoftmodel:asp.net corescope:ltversion:8.0.14

Trust: 1.0

vendor:microsoftmodel:visual studio 2022scope:ltversion:17.10.12

Trust: 1.0

vendor:microsoftmodel:visual studio 2022scope:gteversion:17.8.0

Trust: 1.0

vendor:microsoftmodel:visual studio 2022scope:gteversion:17.12.0

Trust: 1.0

vendor:microsoftmodel:visual studio 2022scope:ltversion:17.13.3

Trust: 1.0

vendor:microsoftmodel:asp.net corescope:ltversion:9.0.3

Trust: 1.0

vendor:microsoftmodel:visual studio 2022scope:ltversion:17.8.19

Trust: 1.0

vendor:microsoftmodel:visual studio 2022scope:gteversion:17.13.0

Trust: 1.0

vendor:microsoftmodel:asp.net corescope:gteversion:8.0.0

Trust: 1.0

vendor:microsoftmodel:asp.net corescope:gteversion:9.0.0

Trust: 1.0

vendor:microsoftmodel:visual studio 2022scope:ltversion:17.12.6

Trust: 1.0

vendor:microsoftmodel:visual studio 2022scope:gteversion:17.10.0

Trust: 1.0

sources: NVD: CVE-2025-24070

CVSS

SEVERITY

CVSSV2

CVSSV3

secure@microsoft.com: CVE-2025-24070
value: HIGH

Trust: 1.0

secure@microsoft.com: CVE-2025-24070
baseSeverity: HIGH
baseScore: 7.0
vectorString: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: HIGH
exploitabilityScore: 2.2
impactScore: 4.7
version: 3.1

Trust: 1.0

sources: NVD: CVE-2025-24070

PROBLEMTYPE DATA

problemtype:CWE-1390

Trust: 1.0

sources: NVD: CVE-2025-24070

EXTERNAL IDS

db:NVDid:CVE-2025-24070

Trust: 1.0

sources: NVD: CVE-2025-24070

REFERENCES

url:https://msrc.microsoft.com/update-guide/vulnerability/cve-2025-24070

Trust: 1.0

url:https://www.herodevs.com/vulnerability-directory/cve-2025-24070

Trust: 1.0

sources: NVD: CVE-2025-24070

SOURCES

db:NVDid:CVE-2025-24070

LAST UPDATE DATE

2025-07-02T23:56:50.126000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2025-24070date:2025-07-02T14:25:46.603

SOURCES RELEASE DATE

db:NVDid:CVE-2025-24070date:2025-03-11T17:16:29.680