CVE-2010-3332
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 67.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 67.48% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-209
- Affected
- microsoft/.net framework
- Source
- secure@microsoft.com
References
- http://blogs.technet.com/b/srd/archive/2010/09/17/understanding-the-asp-net-vulnerability.aspxVendor Advisory
- http://isc.sans.edu/diary.html?storyid=9568Third Party Advisory
- http://pentonizer.com/general-programming/aspnet-poet-vulnerability-what-else-can-i-do/Third Party Advisory
- http://secunia.com/advisories/41409Third Party Advisory
- http://securitytracker.com/id?1024459Third Party Advisory, VDB Entry
- http://threatpost.com/en_us/blogs/new-crypto-attack-affects-millions-aspnet-apps-091310Third Party Advisory
- http://twitter.com/thaidn/statuses/24832350146Broken Link
- http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspxMitigation, Third Party Advisory
- http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryId/2799/Oracle-Padding-Vulnerability-in-ASP-NET.aspxThird Party Advisory
- http://www.ekoparty.org/juliano-rizzo-2010.phpBroken Link
- http://www.microsoft.com/technet/security/advisory/2416728.mspxBroken Link
- http://www.mono-project.com/Vulnerabilities#ASP.NET_Padding_OracleExploit, Third Party Advisory
- http://www.securityfocus.com/bid/43316Third Party Advisory, VDB Entry
- http://www.theinquirer.net/inquirer/news/1732956/security-researchers-destroy-microsoft-aspnet-securityThird Party Advisory
- http://www.troyhunt.com/2010/09/fear-uncertainty-and-and-padding-oracle.htmlExploit, Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2429Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2751Third Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61898Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12365Third Party Advisory
- http://blogs.technet.com/b/srd/archive/2010/09/17/understanding-the-asp-net-vulnerability.aspxVendor Advisory
- http://isc.sans.edu/diary.html?storyid=9568Third Party Advisory
- http://pentonizer.com/general-programming/aspnet-poet-vulnerability-what-else-can-i-do/Third Party Advisory
- http://secunia.com/advisories/41409Third Party Advisory
- http://securitytracker.com/id?1024459Third Party Advisory, VDB Entry
- http://threatpost.com/en_us/blogs/new-crypto-attack-affects-millions-aspnet-apps-091310Third Party Advisory
- http://twitter.com/thaidn/statuses/24832350146Broken Link
- http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspxMitigation, Third Party Advisory
- http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryId/2799/Oracle-Padding-Vulnerability-in-ASP-NET.aspxThird Party Advisory
- http://www.ekoparty.org/juliano-rizzo-2010.phpBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.