Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
References
Link Providers
https://www.spirityenterprise.com/managed-detection-response-microsoft spirity
https://www.spirityenterprise.com/virtual-ciso spirity
http://blogs.technet.com/b/srd/archive/2010/09/17/understanding-the-asp-net-vulnerability.aspx cve-icon cve-icon
http://isc.sans.edu/diary.html?storyid=9568 cve-icon cve-icon
http://pentonizer.com/general-programming/aspnet-poet-vulnerability-what-else-can-i-do/ cve-icon cve-icon
http://secunia.com/advisories/41409 cve-icon cve-icon
http://securitytracker.com/id?1024459 cve-icon cve-icon
http://threatpost.com/en_us/blogs/new-crypto-attack-affects-millions-aspnet-apps-091310 cve-icon cve-icon
http://twitter.com/thaidn/statuses/24832350146 cve-icon cve-icon
http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspx cve-icon cve-icon
http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryId/2799/Oracle-Padding-Vulnerability-in-ASP-NET.aspx cve-icon cve-icon
http://www.ekoparty.org/juliano-rizzo-2010.php cve-icon cve-icon
http://www.microsoft.com/technet/security/advisory/2416728.mspx cve-icon cve-icon
http://www.mono-project.com/Vulnerabilities#ASP.NET_Padding_Oracle cve-icon cve-icon
http://www.securityfocus.com/bid/43316 cve-icon cve-icon
http://www.theinquirer.net/inquirer/news/1732956/security-researchers-destroy-microsoft-aspnet-security cve-icon cve-icon
http://www.troyhunt.com/2010/09/fear-uncertainty-and-and-padding-oracle.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/2429 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/2751 cve-icon cve-icon
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/61898 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12365 cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2024-08-07T03:03:18.963Z

Reserved: 2010-09-14T00:00:00

Link: CVE-2010-3332

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2010-09-22T19:00:06.213

Modified: 2025-04-11T00:51:21.963

Link: CVE-2010-3332

cve-icon Redhat

No data.