Impact
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. The vulnerability is associated with CWE‑345 and CWE‑347 and permits an attacker to supply a forged signature that the framework incorrectly accepts, potentially enabling unauthorized execution or data compromise within any application or service that relies on the vulnerable framework.
Affected Systems
Affected products are Microsoft .NET 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, 4.8.1, .NET 8.0, .NET 9.0, .NET 10.0, and the Microsoft Visual Studio suites including Visual Studio 2017 version 15.9 (covering 15.0‑15.8), Visual Studio 2019 version 16.11 (covering 16.0‑16.10), Visual Studio 2022 versions 17.12 and 17.14, and Visual Studio 2026 versions 18.5 and 18.7. All of these releases contain the vulnerable cryptographic verification component.
Risk and Exploitability
The CVSS score of 8.1 classifies the flaw as high severity while the EPSS score of less than 1% indicates a low probability of exploitation at present; the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote network traffic, inferred from the mention that the bypass can occur over a network. An attacker would need to construct a payload containing a forged signature and send it to the affected application, thereby enabling the attacker to bypass critical security controls implemented by the framework.
OpenCVE Enrichment
Github GHSA
Ubuntu USN