Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2024-0057

.NET: X.509 chain building returns an incorrect failure reason

Technology

.NET

CVSS Score

9.8 / 10.0

Affected Versions

.NET 6.0, 7.0 and 8.0 before the January 2024 releases

Upstream Fix

8.0.1; 7.0.15; 6.0.26

Published

January 9, 2024

OSSeva Coverage

Fixed upstream

Description

When X.509 chain building fails for an untrusted certificate with malformed signatures, .NET correctly reports the failure but returns the wrong reason code. Applications that use the reason code to make their own trust decisions may treat the failure as a successful chain build, which can let an attacker subvert their authentication logic. NVD scores the record 9.8; Microsoft scores it 9.1.

Upstream record: NVD · CVE.org

Is your .NET deployment affected?

If you're running .NET 6.0, 7.0 and 8.0 before the January 2024 releases, you need this patch. Book a discovery call to get covered.