Microsoft .NET Framework ASP.NET Padding Oracle Information Disclosure Vulnerability
BID:43316
Info
Microsoft .NET Framework ASP.NET Padding Oracle Information Disclosure Vulnerability
| Bugtraq ID: | 43316 |
| Class: | Design Error |
| CVE: |
CVE-2010-3332 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2010 12:00AM |
| Updated: | Jun 22 2012 12:20AM |
| Credit: | Thai Duong and Juliano Rizzo |
| Vulnerable: |
Microsoft SharePoint Services 64-bit 2.0 Microsoft SharePoint Services 3.0 SP2 Microsoft SharePoint Services 3.0 SP1 Microsoft SharePoint Server 2010 Standard Edition 0 Microsoft SharePoint Server 2010 Enterprise Edition 0 Microsoft SharePoint Server 2007 x64 SP2 Microsoft SharePoint Server 2007 x64 SP1 Microsoft SharePoint Server 2007 x64 0 Microsoft SharePoint Server 2007 Standard Edition 0 Microsoft SharePoint Server 2007 Enterprise Edition 0 Microsoft SharePoint Server 2007 SP2 Microsoft SharePoint Server 2007 SP1 Microsoft SharePoint Server 2007 12.0.0.6421 Microsoft SharePoint Server 2007 12.0.0.6318 Microsoft SharePoint Server 2007 0 Microsoft .NET Framework 4.0 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.0 Microsoft .NET Framework 2.0 SP2 Microsoft .NET Framework 2.0 SP1 Microsoft .NET Framework 2.0 Microsoft .NET Framework 1.1 SP3 Microsoft .NET Framework 1.1 SP2 Microsoft .NET Framework 1.1 SP1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.0 SP3 Microsoft .NET Framework 1.0 SP2 Microsoft .NET Framework 1.0 SP1 Microsoft .NET Framework 1.0 Gentoo Linux Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Communication Server 1000 Telephony Manager 0 Avaya CallPilot Unified Messaging 0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft .NET Framework ASP.NET Padding Oracle Information Disclosure Vulnerability
Microsoft .NET Framework is prone to an information-disclosure vulnerability in ASP.NET that affects SharePoint.
Successful exploits will allow attackers to decrypt and gain access to potentially sensitive data encrypted by the server or read data from arbitrary files within an ASP.NET application. Obtained information may aid in further attacks.
This issue affects Microsoft .NET Framework versions 4.0 and prior.
Microsoft .NET Framework is prone to an information-disclosure vulnerability in ASP.NET that affects SharePoint.
Successful exploits will allow attackers to decrypt and gain access to potentially sensitive data encrypted by the server or read data from arbitrary files within an ASP.NET application. Obtained information may aid in further attacks.
This issue affects Microsoft .NET Framework versions 4.0 and prior.
Exploit / POC
Microsoft .NET Framework ASP.NET Padding Oracle Information Disclosure Vulnerability
The researchers who discovered this issue have presented a working exploit. This exploit has not been released to the public; however, it is based on the publicly available Padding Oracle Exploit Tool (POET) toolkit.
Multiple tools that leverage this issue are available. Please see the references for more information.
Reportedly, there are limited in-the-wild attacks exploiting this issue.
The following exploit code is available:
The researchers who discovered this issue have presented a working exploit. This exploit has not been released to the public; however, it is based on the publicly available Padding Oracle Exploit Tool (POET) toolkit.
Multiple tools that leverage this issue are available. Please see the references for more information.
Reportedly, there are limited in-the-wild attacks exploiting this issue.
The following exploit code is available:
Solution / Fix
Microsoft .NET Framework ASP.NET Padding Oracle Information Disclosure Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Microsoft .NET Framework 2.0 SP2
Microsoft .NET Framework 3.5
Microsoft .NET Framework 4.0
Microsoft .NET Framework 1.1 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 2.0 SP1
Solution:
Vendor updates are available. Please see the references for more information.
Microsoft .NET Framework 2.0 SP2
-
Microsoft NDP20SP2-KB2418241-IA64.exeNDP20SP2-KB2418241-x64.exeNDP20SP2-KB2418241-x86.exe
http://www.microsoft.com/downloads/details.aspx?familyid=3d31fd37-eb58 -4169-b6b9-4cf854524e46 -
Microsoft Windows6.0-KB2416470-ia64.msuWindows6.0-KB2416470-x64.msuWindows6.0-KB2416470-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=45aa5666-3454 -443c-a224-2076215fef04 -
Microsoft Windows6.0-KB2416474-ia64.msuWindows6.0-KB2416474-x64.msuWindows6.0-KB2416474-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=ac1c77df-34d5 -48d4-9a9d-33dc017ffe93
Microsoft .NET Framework 3.5
-
Microsoft NDP20SP1-KB2416468-IA64.exeNDP20SP1-KB2416468-x64.exeNDP20SP1-KB2416468-x86.exe
http://www.microsoft.com/downloads/details.aspx?familyid=d284237b-e4d9 -460a-98f0-7a18252f5780 -
Microsoft NDP35-KB2418240-IA64.exeNDP35-KB2418240-x64.exeNDP35-KB2418240-x86.exe
http://www.microsoft.com/downloads/details.aspx?familyid=00d95a85-f3e8 -464d-a10c-85c6d91b4aae -
Microsoft Windows6.0-KB2416469-ia64.msuWindows6.0-KB2416469-x64.msuWindows6.0-KB2416469-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=7ad59265-9dca -4731-ac09-46c162c1832a
Microsoft .NET Framework 4.0
-
Microsoft NDP40-KB2416472-IA64.exeNDP40-KB2416472-x64.exeNDP40-KB2416472-x86.exe
http://www.microsoft.com/downloads/details.aspx?familyid=6ce703b7-08a5 -4eff-a062-d5dc720908f6
Microsoft .NET Framework 1.1 SP1
-
Microsoft NDP1.1sp1-KB2416447-X86.exe
http://www.microsoft.com/downloads/details.aspx?familyid=a7990e61-21fd -4942-9dfe-af7961cb0282 -
Microsoft WindowsServer2003-KB2416451-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=71f0daad-e2df -421c-9818-58e1e40cdb65
Microsoft .NET Framework 3.5 SP1
-
Microsoft NDP35SP1-KB2416473-IA64.exeNDP35SP1-KB2416473-x64.exeNDP35SP1-KB2416473-x86.exe
http://www.microsoft.com/downloads/details.aspx?familyid=ae42d6cc-6d4e -425a-9b4f-379f66fc506a -
Microsoft Windows6.1-KB2416471-ia64.msuWindows6.1-KB2416471-x64.msuWindows6.1-KB2416471-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=5e7dcf51-74f1 -43cc-aece-0cd5df05ddb7
Microsoft .NET Framework 2.0 SP1
-
Microsoft Windows6.0-KB2416469-ia64.msuWindows6.0-KB2416469-x64.msuWindows6.0-KB2416469-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=7ad59265-9dca -4731-ac09-46c162c1832a
References
Microsoft .NET Framework ASP.NET Padding Oracle Information Disclosure Vulnerability
References:
References:
- Another video may prove it all (Thai Duong)
- Automated Padding Oracle Attacks with PadBuster (Brian Holyfield)
- Breaking .NET encryption with or without Padding Oracle (MINDED SECURITY RESEARCH LABS)
- Investigating .NET Padding Oracle Exploitation with padBusterdotnet (MINDED SECURITY RESEARCH LABS)
- Microsoft .NET Framework Developer Center (Microsoft)
- Microsoft Homepage (Microsoft)
- Microsoft Security Bulletin Advance Notification for September 2010 (Microsoft)
- MS ASP.NET padding oracle attack mitigation (dragosr)
- Out of Band Release to Address Microsoft Security Advisory 2416728 (Microsoft)
- Practical Padding Oracle Attacks (netifera)
- Security Advisory 2416728 (Vulnerability in ASP.NET) and SharePoint (Microsoft)
- Security Advisory 2416728 - Workaround Update (Microsoft Security Response Center)
- Understanding the ASP.NET Vulnerability (Microsoft)
- Update to Security Advisory 2416728 (Microsoft)
- ASA-2010-252: MS10-070 Vulnerability in ASP.NET Could Allow Information Disclosu (Avaya)
- Microsoft Security Advisory (2416728) (Microsoft)
- Microsoft Security Bulletin MS10-070 (Microsoft)