CybersecuritySoftware

Microsoft Addresses Critical ASP.NET Core Vulnerability in Kestrel Web Server

Microsoft has released patches for a critical vulnerability in ASP.NET Core’s Kestrel web server, rated 9.9 on the CVSS scale. The flaw, involving request smuggling, could bypass security measures depending on application code. Developers are urged to evaluate risks and apply updates promptly.

Critical Security Flaw Identified in ASP.NET Core

Microsoft has addressed a highly critical vulnerability in ASP.NET Core, specifically within its Kestrel web server component, according to reports. The flaw, designated as CVE-2025-55315, has been assigned a CVSS score of 9.9, which sources indicate is the highest ever recorded by Microsoft for such issues. Security program manager Barry Dorrans described it as a “security feature bypass,” emphasizing that the severity reflects worst-case scenarios where the vulnerability could significantly alter security scope.

AISoftware

Microsoft Expands Copilot AI Integration to All Windows 11 Systems

Microsoft is reportedly expanding its Copilot AI capabilities to all Windows 11 computers, regardless of hardware specifications. The enhanced AI assistant can analyze screen content and perform tasks through natural language commands. Privacy considerations remain a key focus as these cloud-dependent features roll out.

Microsoft’s AI Expansion to All Windows 11 Devices

Microsoft is reportedly bringing its Copilot AI features to all Windows 11 computers, according to recent announcements from the company. This move represents a significant shift from Microsoft’s previous focus on specialized Copilot+ PCs with dedicated neural processing units (NPUs). Sources indicate that every Windows 11 computer will now function as an AI-enabled personal computer, capable of running the company’s Copilot AI features regardless of hardware specifications.