Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-55315— ASP.NET Security Feature Bypass Vulnerability

CVSS 9.9 · Critical EPSS 1.45% · P81
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-55315

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ASP.NET Security Feature Bypass Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
HTTP请求的解释不一致性(HTTP请求私运)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft ASP.NET Core 环境问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft ASP.NET Core是美国微软(Microsoft)公司的一框跨平台开源框架。该框架用于构建Web应用、物联网应用和移动后端等基于云的应用程序。 Microsoft ASP.NET Core存在环境问题漏洞,该漏洞源于攻击者利用该漏洞可以绕过某些功能。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
MicrosoftASP.NET Core 2.3 2.3 ~ 2.3.6 -
MicrosoftASP.NET Core 8.0 8.0 ~ 8.0.21 -
MicrosoftASP.NET Core 9.0 9.0 ~ 9.0.10 -
MicrosoftMicrosoft Visual Studio 2022 version 17.10 17.10.0 ~ 17.10.20 -
MicrosoftMicrosoft Visual Studio 2022 version 17.12 17.12.0 ~ 17.12.13 -
MicrosoftMicrosoft Visual Studio 2022 version 17.14 17.14.0 ~ 17.14.17 -

II. Public POCs for CVE-2025-55315

#POC DescriptionSource LinkShenlong Link
1Playground to experiment with different behavior on patched/unpatched Kestrel for the CVE-2025-55315 HTTP smuggling vulnerabilityhttps://github.com/nickcopi/CVE-2025-55315-detection-playgroundPOC Details
2Nonehttps://github.com/sirredbeard/CVE-2025-55315-reproPOC Details
3Nonehttps://github.com/snowcrashlord/CVE-2025-55315POC Details
4Nonehttps://github.com/RootAid/CVE-2025-55315POC Details
5Nonehttps://github.com/digitalsnemesis/CVE-2025-55315POC Details
6专业级HTTP请求走私漏洞利用与自动化渗透测试工具https://github.com/7huukdlnkjkjba/CVE-2025-55315-POC Details
7Quick and Simple Scripts to Scan for Vulnerable Servers and Packet Level Monitorshttps://github.com/jlinebau/CVE-2025-55315-Scanner-MonitorPOC Details
8Nonehttps://github.com/blackquantas/CVE-2025-55315POC Details
9CVE-2025-55315 PoC Exploithttps://github.com/ZemarKhos/CVE-2025-55315-PoC-ExploitPOC Details
10Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle requests past proxies and load balancers in vulnerable ASP.NET Core/Kestrel servers.https://github.com/MartinFabianIonut/CVE-2025-55315POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-55315

登录查看更多情报信息。

Same Patch Batch · Microsoft · 2025-10-14 · 167 CVEs total

CVE-2025-497089.9 CRITICALMicrosoft Graphics Component Elevation of Privilege Vulnerability
CVE-2025-592879.8 CRITICALWindows Server Update Service (WSUS) Remote Code Execution Vulnerability
CVE-2025-587188.8 HIGHRemote Desktop Client Remote Code Execution Vulnerability
CVE-2025-587158.8 HIGHWindows Speech Runtime Elevation of Privilege Vulnerability
CVE-2025-587168.8 HIGHWindows Speech Runtime Elevation of Privilege Vulnerability
CVE-2025-592288.8 HIGHMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2025-592958.8 HIGHWindows URL Parsing Remote Code Execution Vulnerability
CVE-2025-592138.8 HIGHConfiguration Manager Elevation of Privilege Vulnerability
CVE-2025-592378.8 HIGHMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2025-592498.8 HIGHMicrosoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-537828.4 HIGHMicrosoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-592368.4 HIGHMicrosoft Excel Remote Code Execution Vulnerability
CVE-2025-592918.2 HIGHConfidential Azure Container Instances Elevation of Privilege Vulnerability
CVE-2025-592928.2 HIGHAzure Compute Gallery Elevation of Privilege Vulnerability
CVE-2025-592508.1 HIGHJDBC Driver for SQL Server Spoofing Vulnerability
CVE-2025-556967.8 HIGHNtQueryInformation Token function (ntifs.h) Elevation of Privilege Vulnerability
CVE-2025-592777.8 HIGHWindows Authentication Elevation of Privilege Vulnerability
CVE-2025-556947.8 HIGHWindows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2025-531507.8 HIGHWindows Digital Media Elevation of Privilege Vulnerability
CVE-2025-592077.8 HIGHWindows Kernel Elevation of Privilege Vulnerability

Showing top 20 of 167 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2025-55315

No comments yet


Leave a comment