Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry.
History

Thu, 10 Jul 2025 17:45:00 +0000

Type Values Removed Values Added
References

Thu, 10 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
References

Tue, 08 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Jul 2025 14:45:00 +0000

Type Values Removed Values Added
Description Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry.
Title EOL ASP.NET Core Elevation of Privilege Vulnerability
Weaknesses CWE-1390
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HeroDevs

Published: 2025-07-08T14:31:45.633Z

Updated: 2025-07-10T17:30:15.501Z

Reserved: 2025-07-07T15:43:27.241Z

Link: CVE-2025-7326

cve-icon Vulnrichment

Updated: 2025-07-08T15:05:40.408Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-08T15:15:34.623

Modified: 2025-07-10T17:15:48.623

Link: CVE-2025-7326

cve-icon Redhat

No data.