Microsoft warns of .Net vulnerability

Microsoft offers workaround and prepares patch after researchers reveal hole in ASP.Net software used in millions of Web sites.


Microsoft is warning people of a potentially serious vulnerability in its ASP.Net framework used to create Web sites.

The hole affects all versions of the .Net framework and affects Windows XP, Vista, Windows 7, and Windows Server 2003 and 2008, company said in an advisory released late on Friday.

"At this time we are not aware of any attacks using this vulnerability and we encourage customers to review the advisory for mitigations and workarounds," the company said in a blog post.

Microsoft also provided a script to help administrators determine if their ASP.Net applications are vulnerable.

The vulnerability is caused by ASP.Net providing Web clients details in error messages when decrypting certain ciphertext, Microsoft said. An attacker could be able to read or tamper with data that was encrypted by the server, as well as read data from files on the target server.

Microsoft's security advisory came after two researchers presented a talk on the vulnerability at the Ekoparty security conference in Buenos Aires on Friday.

"You can decrypt cookies, view states, form authentication tickets, membership password, user data, and anything else encrypted using the framework's API!" the researchers said in the description of their talk on the conference Web site. "The vulnerabilities exploited affect the framework used by 25 percent of the Internet websites. The impact of the attack depends on the applications installed on the server, from information disclosure to total system compromise."

Featured Video
This content is rated TV-MA, and is for viewers 18 years or older. Are you of age?
Sorry, you are not old enough to view this content.

Details about Apple's 'spaceship' campus from the drone pilot who flies over it

MyithZ has one of the most popular aerial photography channels on YouTube. With the exception of revealing his identity, he is an open book as he shares with CNET's Brian Tong the drone hardware he uses to capture flyover shots of the construction of Apple's new campus, which looks remarkably like an alien craft.

by Brian Tong