{"id":405690,"date":"2026-04-22T20:28:08","date_gmt":"2026-04-22T20:28:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/il\/405690\/"},"modified":"2026-04-22T20:28:08","modified_gmt":"2026-04-22T20:28:08","slug":"microsoft-issues-emergency-update-for-macos-and-linux-asp-net-threat","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/il\/405690\/","title":{"rendered":"Microsoft issues emergency update for macOS and Linux ASP.NET threat"},"content":{"rendered":"<p>Microsoft released an emergency patch for its ASP.NET Core to fix a high-severity vulnerability that allows unauthenticated attackers to gain SYSTEM privileges on devices that use the Web development framework to run Linux or macOS apps.<\/p>\n<p>The software maker <a href=\"https:\/\/github.com\/dotnet\/announcements\/issues\/395\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> Tuesday evening that the vulnerability, tracked as CVE-2026-40372, affects versions 10.0.0 through 10.0.6 of the <a href=\"https:\/\/www.nuget.org\/packages\/Microsoft.AspNetCore.DataProtection\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft.AspNetCore.DataProtection<\/a> NuGet, a package that\u2019s part of the framework. The critical flaw stems from a faulty verification of cryptographic signatures. It can be exploited to allow unauthenticated attackers to forge authentication payloads during the <a href=\"https:\/\/learn.microsoft.com\/en-us\/dotnet\/api\/system.security.cryptography.hmac?view=net-10.0#remarks\" rel=\"nofollow noopener\" target=\"_blank\">HMAC validation<\/a> process, which is used to verify the integrity and authenticity of data exchanged between a client and a server.<\/p>\n<p>Beware: Forged credentials survive patching<\/p>\n<p>During the time users ran a vulnerable version of the package, they were left open to an attack that would allow unauthenticated people to gain sensitive SYSTEM privileges that would allow full compromise of the underlying machine. Even after the vulnerability is patched, devices may still be compromised if authentication credentials created by a threat actor aren\u2019t purged.<\/p>\n<p>\u201cIf an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves,\u201d Microsoft said. \u201cThose tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated.\u201d<\/p>\n<p>Microsoft <a href=\"https:\/\/dotnet.microsoft.com\/en-us\/learn\/aspnet\/what-is-aspnet-core\" rel=\"nofollow noopener\" target=\"_blank\">describes<\/a> ASP.NET Core as a \u201chigh-performance\u201d web development framework for writing .Net apps that run on Windows, macOS, Linux, and Docker. The open-source package is \u201cdesigned to allow runtime components, APIs, compilers, and languages [to] evolve quickly, while still providing a stable and supported platform to keep apps running.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft released an emergency patch for its ASP.NET Core to fix a high-severity vulnerability that allows unauthenticated attackers&hellip;\n","protected":false},"author":2,"featured_media":344168,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[85,46,125],"class_list":{"0":"post-405690","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-il","9":"tag-israel","10":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/405690","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/comments?post=405690"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/405690\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media\/344168"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media?parent=405690"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/categories?post=405690"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/tags?post=405690"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}