More

    Microsoft fixes one of its “highest ever” rated security flaws – here’s what happened




    • CVE-2025-55315 enables HTTP request smuggling in ASP.NET Core’s Kestrel web server
    • Attackers can bypass controls, access credentials, alter files, or crash the server
    • Microsoft released updates for affected .NET and Visual Studio versions to mitigate the flaw

    Microsoft has confirmed it recently fixed its “highest ever” vulnerability plaguing its ASP.NET Core product.

    Described as an “HTTP request smuggling bug”, the vulnerability is tracked as CVE-2025-55315, and was given a severity score of 9.9/10 (critical).


    https://cdn.mos.cms.futurecdn.net/YsReok3f8M9yESRDbeGJVH-970-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img