Microsoft fixes one of its “highest ever” rated security flaws – here’s what happened

  • CVE-2025-55315 enables HTTP request smuggling in ASP.NET Core’s Kestrel web server
  • Attackers can bypass controls, access credentials, alter files, or crash the server
  • Microsoft released updates for affected .NET and Visual Studio versions to mitigate the flaw

Microsoft has confirmed it recently fixed its “highest ever” vulnerability plaguing its ASP.NET Core product.

Described as an “HTTP request smuggling bug”, the vulnerability is tracked as CVE-2025-55315, and was given a severity score of 9.9/10 (critical).

It affects the Kestrel ASP.NET Core web server and allows unauthenticated attackers to “smuggle” secondary HTTP requests within the original request.

How to update

The smuggled one can help the attackers bypass different security controls; it was explained.

“An attacker who successfully exploited this vulnerability could view sensitive information such as other user’s credentials (Confidentiality) and make changes to file contents on the target server (Integrity), and they might be able to force a crash within the server (Availability),” Microsoft explained in its security advisory.

Depending on which versions you are running, there are different ways to secure your infrastructure from potential attacks.

Those running .NET 8 or later should install the .NET update from Microsoft Update, while those running .NET 2.3 should update the package reference for Microsoft.AspNet.Server.Kestrel.Core to 2.3.6, then recompile the application, and redeploy. Those running a self-contained/single-file application should install the .NET update, recompile, and redeploy.

Microsoft has also released security updates for Microsoft Visual Studio 2022, ASP.NET Core 2.3, ASP.NET Core 8.0, and ASP.NET Core 9.0, as well as the Microsoft.AspNetCore.Server.Kestrel.Core package for ASP.NET Core 2.x apps.

On GitHub, .NET security technical program manager Barry Dorrans said that the bug’s score would be “nowhere near that high”, but scores are based on how the bug might affect applications built on top of ASP.NET, so it really comes down to each individual app:

“We don’t know what’s possible because it’s dependent on how you’ve written your app,” he said. “Thus, we score with the worst possible case in mind, a security feature bypass which changes scope.”

Via The Register

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Read more @ TechRadar

Latest posts

Worrying WatchGuard VPN bug could let hackers hijack your devices – here’s how to stay safe

CVE-2025-9242 allows unauthenticated remote code execution on WatchGuard Fireware devicesVulnerability affects VPN configurations using IKEv2 with dynamic gateway peersBusinesses should patch affected versions and...

China claims the US NSA conducted cyberattacks on its national time center

China has accused the US of cyber-espionageChina's National Time Service Center was breached through security flaws in employee phonesThe two states have been pointing...

Attention audiobook lovers! You can get three books for just $3 / £3 with this seasonal Audible deal

Listen up, audiobook fans. I have a corker of a deal for you that means you can get a three-month Audible Premium Plus membership...

Quordle hints and answers for Tuesday, October 21 (game #1366)

Looking for a different day?A new Quordle puzzle appears at midnight each day for your time zone – which means that some people are...

NYT Connections hints and answers for Tuesday, October 21 (game #863)

Looking for a different day?A new NYT Connections puzzle appears at midnight each day for your time zone – which means that some people...

NYT Strands hints and answers for Tuesday, October 21 (game #597)

Looking for a different day?A new NYT Strands puzzle appears at midnight each day for your time zone – which means that some people...

Can’t wait for Frankenstein? Guillermo Del Toro says there are “hints” of the new Netflix movie in his earlier films

Guillermo Del Toro's Frankenstein comes to Netflix on November 7The filmmaker revealed that his previous films have hints of his vision for the adaptation...

Critical national infrastructure can’t afford to delay PSTN migration

The UK's analogue Public Switched Telephone Network (PSTN) is in its final phase. The current network was designed to support the nation’s first telephone...

The iPhone Air might not be selling too well, but I hope Apple doesn’t give up on its most exciting phone in years –...

As we recently reported, early sales of the iPhone Air might not be looking too strong. Morgan Stanley has reported a ‘relative weakness’ in...

This Lenovo Legion 5 gaming laptop is $500 off today and it features not just an RTX 5060, but also an OLED screen

Has the demise of Windows 10 made you realise you need to upgrade your existing rig? For gamers, I’ve spotted one of the best...