CVE-2025-24070
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
- Affected products
- Alt Linux, Asp.Net Core, Almalinux, Centos, Linuxmint, Red Hat, Red Os, Rocky Linux
- Microsoft Asp.net Core
- < 8.0.14, 9.0.3
- Microsoft Visual Studio 2022
- < 17.8.19, 17.10.12, 17.12.6, 17.13.3
- Fix
- Available
- CVSS 3.1
- 7.0 HIGH
- EPSS
- 0.9% (57th percentile)
- Weakness
- CWE-1390
- NVD status
- Analyzed
- Published
- 2025-03-11
CVE-2025-24070 at NVD
No indexed exploits for CVE-2025-24070 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-24070 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.