Impact
Recently released information shows that a flaw in the attribute certificate path validator of Bouncy Castle’s bc‑csharp library allows a remote attacker to create a forged X.509 attribute certificate that passes all correctness checks—apart from the actual signature verification step. Because the validator does not confirm that the certificate’s signature matches the issuer’s public key, an attacker can inject arbitrary attributes or roles into an application. This enables the attacker to receive any privileges or access rights the application grants based on those attributes, effectively escalating their permissions within the affected system.
Affected Systems
The vulnerability affects the bc‑csharp library from Bouncy Castle, specifically versions prior to 2.7.0. Only applications that explicitly invoke the PkixAttrCertPathValidator or PkixAttrCertPathBuilder classes for processing attribute certificates are impacted. Users should verify whether their code performs such validation and whether any earlier versions of bc‑csharp are in use.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity overall, while the EPSS score is not publicly available, so an exact likelihood of exploitation cannot be estimated. The issue is not listed in the CISA KEV catalog, suggesting that there is no documented exploitation of this specific flaw at the time of analysis. Nevertheless, the flaw can be exploited remotely by supplying a forged attribute certificate to an application that trusts the library for validation. Breaches would most likely arise from malicious input or compromised configuration that allows untrusted certificates to be processed, resulting in an unauthorized elevation of privileges.
OpenCVE Enrichment