CVE-2024-0057
.NET: X.509 chain building returns an incorrect failure reason
Technology
.NET
CVSS Score
9.8 / 10.0
Affected Versions
.NET 6.0, 7.0 and 8.0 before the January 2024 releases
Upstream Fix
8.0.1; 7.0.15; 6.0.26
Published
January 9, 2024
OSSeva Coverage
Fixed upstream
Description
When X.509 chain building fails for an untrusted certificate with malformed signatures, .NET correctly reports the failure but returns the wrong reason code. Applications that use the reason code to make their own trust decisions may treat the failure as a successful chain build, which can let an attacker subvert their authentication logic. NVD scores the record 9.8; Microsoft scores it 9.1.
Is your .NET deployment affected?
If you're running .NET 6.0, 7.0 and 8.0 before the January 2024 releases, you need this patch. Book a discovery call to get covered.