Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Samsung showed me its secret HDR10+ Advanced TV samples – and I’m almost sold

    November 8, 2025

    Starbucks barista’s side hustle brings in $1 million a month

    November 8, 2025

    A new Chinese AI model claims to outperform GPT-5 and Sonnet 4.5 – and it’s free

    November 8, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Microsoft fixes highest-severity ASP.NET Core flaw to date
    Security

    Microsoft fixes highest-severity ASP.NET Core flaw to date

    PineapplesUpdateBy PineapplesUpdateOctober 17, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Microsoft fixes highest-severity ASP.NET Core flaw to date
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft fixes highest-severity ASP.NET Core flaw to date

    Earlier this week, Microsoft fixed a vulnerability that was marked with the “highest” severity rating ever received by an ASP.NET Core security flaw.

    This HTTP request smuggling bug (CVE-2025-55315) Kestrel was found in the ASP.NET Core web server, and it enables authenticated attackers to hijack other users’ credentials or smuggle another HTTP request to bypass front-end security controls.

    “An attacker who successfully exploited this vulnerability could view sensitive information such as another user’s credentials (confidentiality) and make changes to file contents on the target server (integrity), and they may be able to force a crash within the server (availability),” Microsoft said in a statement. tuesday advice,

    To ensure that their ASP.NET Core applications are protected from potential attacks, Microsoft recommends developers and users take the following measures:

    • If running .NET 8 or later, install the .NET update from Microsoft Update, then restart your application or restart the machine.
    • If running .NET 2.3, update the package reference for Microsoft.AspNet.Server.Kestrel.Core to 2.3.6, then recompile the application, and redeploy.
    • If running a self-contained/single-file application, install the .NET update, recompile, and re-deploy.

    To address the vulnerability, Microsoft has released a security update Microsoft.AspNetCore.Server.Kestrel.Core package for Microsoft Visual Studio 2022, ASP.NET Core 2.3, ASP.NET Core 8.0, and ASP.NET Core 9.0, as well as ASP.NET Core 2.x apps.

    As .NET Security Technical Program Manager Barry Dorrans explained, the impact of CVE-2025-55315 attacks will depend on the targeted ASP.NET application, and successful exploitation could allow threat actors to log in as a different user (for privilege escalation), make internal requests (in server-side request forgery attacks), cross-site request forgery (CSRF) detection, This may allow bypassing or injection attacks.

    “But we don’t know what’s possible because it depends on how you wrote your app. Thus, we score taking into account the worst possible case, a security feature bypass that changes the scope,” Dorrans said,

    “Is that a possibility? No, probably not unless your application code is doing something strange and skipping several checks that it should do on every request. Still please update.”

    During this month’s Patch Tuesday, Microsoft released security updates for 172 vulnerabilities, including eight “critical” vulnerabilities and six zero-day bugs (three of which were exploited in attacks).

    This week, Microsoft also published KB5066791, a cumulative update that contains the final Windows 10 security updates as the operating system reaches the end of its support lifecycle.


    picus blue report 2025

    Passwords were cracked in 46% of environments, almost double from 25% last year.

    Get the Picus Blue Report 2025 now for a comprehensive look at prevention, detection, and more findings on data intrusion trends.

    ASP.NET core date fixes Flaw highestseverity Microsoft
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleACE prevents context collapse with ‘evolved playbook’ for self-improving AI agents
    Next Article Crypto’s Next Chapter Disrupts in 2025 with Solana’s Anatoly Yakovenko
    PineapplesUpdate
    • Website

    Related Posts

    AI/ML

    Strengthening our core: Welcoming Carine Levy as VentureBeat’s new managing editor

    November 3, 2025
    Startups

    Microsoft Said My PC Can’t Run Windows 11, But I Still Upgraded in 5 Minutes – Here’s How

    October 30, 2025
    AI/ML

    OpenAI has an AGI problem – and Microsoft made it worse

    October 29, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Samsung showed me its secret HDR10+ Advanced TV samples – and I’m almost sold

    November 8, 2025

    Starbucks barista’s side hustle brings in $1 million a month

    November 8, 2025

    A new Chinese AI model claims to outperform GPT-5 and Sonnet 4.5 – and it’s free

    November 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.