logo

Microsoft out-of-band updates fixed critical ASP.NET Core privilege escalation flaw

ID: d4ea1b08-8fc8-5dc5-996d-18698abbade9

STIX ID: report--d4ea1b08-8fc8-5dc5-996d-18698abbade9

Feed Name: Security Affairs

Threat Score
72/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Microsoft released out-of-band updates to fix a critical ASP.NET Core vulnerability (CVE-2026-40372, CVSS 9.1) in Microsoft.AspNetCore.DataProtection 10.0.0–10.0.6 that allowed improper HMAC validation, enabling attackers to forge or decrypt protected data (cookies, antiforgery tokens) and potentially escalate to SYSTEM on non-Windows hosts; Microsoft patched the issue in ASP.NET Core 10.0.7 but warns that previously issued tokens remain valid unless the DataProtection key ring is rotated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.