Skip to content

ASP.NET Core Elevation of privilege Vulnerability

Critical
rbhanda published GHSA-crgg-f857-pvc7 Dec 14, 2021

Package

aspnetcorev2_inprocess.dll (Binary)

Affected versions

16.0.21299.0, <= 15.0.21297.12, < = 13.1.21296.21

Patched versions

16.0.21322.1, >= 15.0.21326.13, >= 13.1.21333.22

Description

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET and .NET Core. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An elevation of privilege vulnerability exists in ANCM which could allow elevation of privilege when .NET core, .NET 5 and .NET 6 applications are hosted within IIS.

Affected Software

Only applications hosted under IIS are vulnerable. If you use Kestrel as your web hosts you are not vulnerable.

  • Any .NET 6.0 application hosted in IIS running on ANCM version 16.0.21299.0
  • Any .NET 5.0 application hosted in IIS running on ANCM version 15.0.21297.12 or lower
  • Any .NET Core 3.1 application hosted in IIS running on ANCM version 13.1.21296.21 or lower

You can check the ANCM version of the affected binary aspnetcorev2_inprocess.dll from "C:\Program Files\IIS\Asp.Net Core Module\V2"

Patches

To fix the issue, please install the latest version of hosting bundle.

Other Details

Severity

Critical

CVE ID

CVE-2021-43877

Weaknesses

No CWEs