INFSA-2025:2667: .NET 9.0 security update
Information about definition
Identificator: INFSA-2025:2667
Type: security
Release date: 2025-03-31 09:02:47 UTC
Information about package
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.104 and .NET Runtime 9.0.3.
Vulnerabilities description
- CVE-2025-24070
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2025-24070
|
no information | 7.8 | no information |
Updated packages