CWE-556

ASP.NET Misconfiguration: Use of Identity Impersonation

High

Description

Configuring an ASP.NET application to run with impersonated credentials may give the application unnecessary privileges.

Potential Impact

How to Fix

Architecture and Design

Use the least privilege principle.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-556 vulnerabilities in your codebase.

Get Security Assessment