About this tag
MS10-070 is a Microsoft security bulletin addressing a vulnerability in ASP.NET that could allow information disclosure. Known as the ASP.NET Padding Oracle Vulnerability (CVE-2010-3332), it affects all versions of the .NET Framework when used on Windows Server operating systems. An attacker exploiting this vulnerability could read encrypted data such as view state. Microsoft released this update out-of-band in September 2010, and it was distributed through Windows Update, Windows Server Update Services, and other channels. The bulletin also includes corrected Server Core installation applicability for .NET Framework 4 on Windows Server 2008 R2. Users are strongly encouraged to apply the security update promptly.
-
Summary for September 2010 - Version: 6.1
Revision Note: V6.1 (October 26, 2011): For MS10-070, corrected Server Core installation applicability for .NET Framework 4 on Windows Server 2008 R2 for x64-based Systems. Summary: This bulletin summary lists security bulletins released for September 2010. More...- News
- Thread
- 2010 bulletin ms10-070 net framework revision note security windows server x64
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2416728): Vulnerability in ASP.NET Could Allow Information Disclosure -
Revision Note: V2.0 (September 28, 2010): Advisory updated to reflect publication of security bulletin Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-070 to address this issue. For more information about this issue...- News
- Thread
- advisory asp.net cve-2010-3332 information information disclosure microsoft ms10-070 security update vulnerability
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2416728): Vulnerability in ASP.NET Could Allow Information Disclosure
Revision Note: V2.0 (September 28, 2010): Advisory updated to reflect publication of security bulletinSummary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-070 to address this issue. For more information about this issue, including...- News
- Thread
- advisory asp.net cve-2010-3332 information information disclosure microsoft ms10-070 security update vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS10-070 Released Out-of-Band Today
Hello, As we announced yesterday, today we released Link Removed due to 404 Error out-of-band to address a vulnerability in ASP.NET. The bulletin and the blog by Scott Guthrie, corporate vice president of Microsoft's .NET Developer Platform are available for more information. This security...- News
- Thread
- asp.net automatic updates framework ms10-070 security trustworthy computing update vulnerability webcast windows server
- Replies: 0
- Forum: Security Alerts
-
Microsoft Releases MS10-070 to all distribution channels
Hi everyone - Today we released out-of-band Link Removed due to 404 Errorthrough the remainder of our standard distribution channels, including Windows Update and Windows Server Update Services. We have completed our testing of these channels and confirmed the update can be successfully...- News
- Thread
- automatic updates deployment microsoft ms10-070 security testing trustworthy computing update webcast windows update
- Replies: 0
- Forum: Security Alerts