Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Microsoft fixes one of its “highest ever” rated security flaws – here’s what happened

Tech Wavo by Tech Wavo
October 20, 2025
in Computers
0




  • CVE-2025-55315 enables HTTP request smuggling in ASP.NET Core’s Kestrel web server
  • Attackers can bypass controls, access credentials, alter files, or crash the server
  • Microsoft released updates for affected .NET and Visual Studio versions to mitigate the flaw

Microsoft has confirmed it recently fixed its “highest ever” vulnerability plaguing its ASP.NET Core product.

Described as an “HTTP request smuggling bug”, the vulnerability is tracked as CVE-2025-55315, and was given a severity score of 9.9/10 (critical).

It affects the Kestrel ASP.NET Core web server and allows unauthenticated attackers to “smuggle” secondary HTTP requests within the original request.


You may like

How to update

The smuggled one can help the attackers bypass different security controls; it was explained.

“An attacker who successfully exploited this vulnerability could view sensitive information such as other user’s credentials (Confidentiality) and make changes to file contents on the target server (Integrity), and they might be able to force a crash within the server (Availability),” Microsoft explained in its security advisory.

Depending on which versions you are running, there are different ways to secure your infrastructure from potential attacks.

Those running .NET 8 or later should install the .NET update from Microsoft Update, while those running .NET 2.3 should update the package reference for Microsoft.AspNet.Server.Kestrel.Core to 2.3.6, then recompile the application, and redeploy. Those running a self-contained/single-file application should install the .NET update, recompile, and redeploy.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Microsoft has also released security updates for Microsoft Visual Studio 2022, ASP.NET Core 2.3, ASP.NET Core 8.0, and ASP.NET Core 9.0, as well as the Microsoft.AspNetCore.Server.Kestrel.Core package for ASP.NET Core 2.x apps.

On GitHub, .NET security technical program manager Barry Dorrans said that the bug’s score would be “nowhere near that high”, but scores are based on how the bug might affect applications built on top of ASP.NET, so it really comes down to each individual app:

“We don’t know what’s possible because it’s dependent on how you’ve written your app,” he said. “Thus, we score with the worst possible case in mind, a security feature bypass which changes scope.”

Via The Register


Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Previous Post

The Samsung S95F is our TV of the year – here’s how Samsung beat elite OLED and mini-LED TVs from the likes of LG and Sony

Next Post

Intel’s new data center GPU bets on cheaper LPDDR5X memory and skips the high-cost AI accelerator race

Next Post
I got to see Intel Panther Lake up close this month, and it is the most important product Intel has ever produced

Intel’s new data center GPU bets on cheaper LPDDR5X memory and skips the high-cost AI accelerator race

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Fujitsu shocks tech fans with a 16-inch laptop that still plays DVDs, while other makers chase cloud and speed trends

by Tech Wavo
October 20, 2025
0
Fujitsu shocks tech fans with a 16-inch laptop that still plays DVDs, while other makers chase cloud and speed trends
Computers

Fujitsu A77-K3 has an optical drive and Intel Core processorThe A77-K3’s large display and solid build target long-hour productivity usersFujitsu...

Read more

Top OpenAI, Google Brain researchers set off a $300M VC frenzy for their startup Periodic Labs 

by Tech Wavo
October 20, 2025
0
Top OpenAI, Google Brain researchers set off a $300M VC frenzy for their startup Periodic Labs 
Computers

Periodic Labs, a new startup by one of OpenAI’s most respected researchers, Liam Fedus, and his former Google Brain colleague,...

Read more

A Human-Centered Approach to Competitive Advantage – O’Reilly

by Tech Wavo
October 20, 2025
0
A Human-Centered Approach to Competitive Advantage – O’Reilly
News

In the modern enterprise, information is the new capital. While companies pour resources into artificial intelligence, many discover that technology,...

Read more

Can engineering catch up with quantum physics and bring us useful quantum computing

by Tech Wavo
October 20, 2025
0
Can engineering catch up with quantum physics and bring us useful quantum computing
Computers

As quantum computing is attracting unprecedented investment, with $3 billion flowing into the sector in just the first half of...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock