Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with ASP.NET Core 3.1.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-43877HIGH | ASP.NET Core and Visual Studio Elevation of Privilege VulnerabilityASP.NET Core and Visual Studio Elevation of Privilege Vulnerability Dec 15, 2021 | CVSS8.8v3.1 | EPSS0.716% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-34532MEDIUM | ASP.NET Core and Visual Studio Information Disclosure VulnerabilityMicrosoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 where a JWT token is logged if it cannot be parsed. ### Patches * If you're using .NET 5.0, you should download and install Runtime 5.0.9 or SDK 5… Aug 12, 2021 | CVSS5.5v3.1 | EPSS1.21% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-1723HIGH | ASP.NET Core and Visual Studio Denial of Service VulnerabilityA denial-of-service vulnerability exists in the way Kestrel parses HTTP/2 requests. The security update addresses the vulnerability by fixing the way the Kestrel parses HTTP/2 requests. Users are advised to upgrade. Jan 12, 2021 | CVSS7.5v3.1 | EPSS4.91% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1045HIGH | Microsoft ASP.NET Core Security Feature Bypass VulnerabilityA security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Sep 11, 2020 | CVSS7.5v3.1 | EPSS5.97% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1597HIGH | ASP.NET Core Denial of Service VulnerabilityA denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka `ASP.NET Core Denial of Service Vulnerability`. CWE-20Aug 17, 2020 | CVSS7.5v3.1 | EPSS6.56% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |