Microsoft fixes one of its “highest ever” rated security flaws – here’s what happened




  • CVE-2025-55315 enables HTTP request smuggling in ASP.NET Core’s Kestrel web server
  • Attackers can bypass controls, access credentials, alter files, or crash the server
  • Microsoft released updates for affected .NET and Visual Studio versions to mitigate the flaw

Microsoft has confirmed it recently fixed its “highest ever” vulnerability plaguing its ASP.NET Core product.

Described as an “HTTP request smuggling bug”, the vulnerability is tracked as CVE-2025-55315, and was given a severity score of 9.9/10 (critical).


https://cdn.mos.cms.futurecdn.net/YsReok3f8M9yESRDbeGJVH-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img