Vulnerability record · CVE-2010-3332 · published 22 September 2010
CVE-2010-3332: ASP.NET View State padding oracle leaks decryption details
Microsoft · .Net Framework
Microsoft .NET Framework versions used by ASP.NET in IIS return detailed error codes during decryption attempts, creating a padding oracle. A remote attacker can use those error differences to decrypt and modify encrypted View State (__VIEWSTATE) form data, and possibly forge cookies or read application files.
Description
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
AV:N/AC:L/Au:N/C:P/I:P/A:N
Automated analysis
high priorityRemote, unauthenticated exploitation with public techniques and very high EPSS, though impact is partial confidentiality and integrity rather than full compromise.
What it is
Microsoft .NET Framework versions used by ASP.NET in IIS return detailed error codes during decryption attempts, creating a padding oracle. A remote attacker can use those error differences to decrypt and modify encrypted View State (__VIEWSTATE) form data, and possibly forge cookies or read application files.
Impact
An attacker can recover and tamper with encrypted View State, potentially forging authentication cookies or reading application files, which can lead to data disclosure or request forgery against the application.
Attack surface
Reachable over the network via HTTP requests to an ASP.NET application; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.67481, 99.27th percentile) and multiple references are tagged Exploit, indicating public exploitation techniques exist.
What to do
- Apply Microsoft security update MS10-070 for the affected .NET Framework versions.
- Enable View State MAC and use unique, strong machine keys per application.
- Configure custom error handling so decryption failures do not return distinguishable error codes.
- Rotate machine keys and invalidate existing View State and cookies after patching.
- Monitor vendor guidance for any additional configuration hardening.
Detection
- Alert on repeated HTTP responses with decryption or View State validation errors from the same source.
- Look for high-volume, systematically varying __VIEWSTATE parameters in web logs.
- Monitor for anomalous cookie values or View State data that fail MAC validation.
- Correlate error-code response patterns with requests to ASP.NET endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-3332 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-3332), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.