Microsoft issues emergency update for macOS and Linux ASP.NET threat



Microsoft released an emergency patch for its ASP.NET Core to fix a high-severity vulnerability that allows unauthenticated attackers to gain SYSTEM privileges on devices that use the Web development framework to run Linux or macOS apps.

The software maker said Tuesday evening that the vulnerability, tracked as CVE-2026-40372, affects versions 10.0.0 through 10.0.6 of the Microsoft.AspNetCore.DataProtection NuGet, a package that’s part of the framework. The critical flaw stems from a faulty verification of cryptographic signatures. It can be exploited to allow unauthenticated attackers to forge authentication payloads during the HMAC validation process, which is used to verify the integrity and authenticity of data exchanged between a client and a server.

Beware: Forged credentials survive patching

During the time users ran a vulnerable version of the package, they were left open to an attack that would allow unauthenticated people to gain sensitive SYSTEM privileges that would allow full compromise of the underlying machine. Even after the vulnerability is patched, devices may still be compromised if authentication credentials created by a threat actor aren’t purged.

“If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves,” Microsoft said. “Those tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated.”

Microsoft describes ASP.NET Core as a “high-performance” web development framework for writing .Net apps that run on Windows, macOS, Linux, and Docker. The open-source package is “designed to allow runtime components, APIs, compilers, and languages [to] evolve quickly, while still providing a stable and supported platform to keep apps running.”



Source link

  • Related Posts

    Chinese hackers are using everyday devices to hack UK firms, warns watchdog | Cybercrime

    British businesses are being urged to step up their vigilance against a China-linked hacking ploy that uses everyday devices for espionage. The UK’s National Cyber Security Centre (NCSC) and agencies…

    Meta will show parents the topics of their teens’ AI conversations

    With countries banning social media for kids left and right, Meta is trying different things to convince parents that its platforms are safe for teens. In its latest effort, the…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Spirit Airlines Nears Rescue Deal With Trump Administration

    Spirit Airlines Nears Rescue Deal With Trump Administration

    Chinese hackers are using everyday devices to hack UK firms, warns watchdog | Cybercrime

    Chinese hackers are using everyday devices to hack UK firms, warns watchdog | Cybercrime

    Content Creator Completes Record-Breaking Charity Stream, But Viewers Still Find Something To Complain About

    Content Creator Completes Record-Breaking Charity Stream, But Viewers Still Find Something To Complain About

    Europe’s resistance to Chinese investment has stalled

    Ukraine gets US$106B loan package from EU after Hungary changes vote – National

    Ukraine gets US$106B loan package from EU after Hungary changes vote – National

    Patriots’ Mike Vrabel to seek counseling, will not be with team for Day 3 of the NFL Draft

    Patriots’ Mike Vrabel to seek counseling, will not be with team for Day 3 of the NFL Draft