CVE-2010-3332
Last modified
CVE-2010-3332 is a vulnerability of currently unknown severity. Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability.". EPSS estimates a 67.48% chance of exploitation in the next 30 days.
Description
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | .Net Framework | 1.1 | Sp1 |
| Microsoft | .Net Framework | 2.0 | Sp1 |
| Microsoft | .Net Framework | 3.5 | — |
| Microsoft | .Net Framework | 3.5.1 | — |
| Microsoft | .Net Framework | 4.0 | — |
References
- http://isc.sans.edu/diary.html?storyid=9568Third Party Advisory
- http://secunia.com/advisories/41409Third Party Advisory
- http://securitytracker.com/id?1024459Third Party Advisory, VDB Entry
- http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspxMitigation, Third Party Advisory
- http://www.mono-project.com/Vulnerabilities#ASP.NET_Padding_OracleExploit, Third Party Advisory
- http://www.securityfocus.com/bid/43316Third Party Advisory, VDB Entry
- http://www.troyhunt.com/2010/09/fear-uncertainty-and-and-padding-oracle.htmlExploit, Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2429Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2751Third Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61898Third Party Advisory, VDB Entry
- http://isc.sans.edu/diary.html?storyid=9568Third Party Advisory
- http://secunia.com/advisories/41409Third Party Advisory
- http://securitytracker.com/id?1024459Third Party Advisory, VDB Entry
- http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspxMitigation, Third Party Advisory
- http://www.mono-project.com/Vulnerabilities#ASP.NET_Padding_OracleExploit, Third Party Advisory
- http://www.securityfocus.com/bid/43316Third Party Advisory, VDB Entry
- http://www.troyhunt.com/2010/09/fear-uncertainty-and-and-padding-oracle.htmlExploit, Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2429Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2751Third Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61898Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3332?
How severe is CVE-2010-3332?
How do I fix CVE-2010-3332?
Are you affected by CVE-2010-3332?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
