CVE-2010-3332 is an ASP.NET cryptographic error-handling flaw in Microsoft .NET Framework 1.1 SP1, 2.0 SP1/SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0 when used for ASP.NET on IIS. The application exposes distinguishable error responses during decryption and padding verification of encrypted ASP.NET data, creating a padding oracle. A remote attacker can use these differences to iteratively decrypt protected values such as View State and to modify encrypted payloads so that the server accepts attacker-controlled data. On .NET Framework 3.5 SP1 and later, the flaw can also be leveraged to disclose arbitrary files within the ASP.NET application, including sensitive configuration files. Microsoft addressed the issue by changing ASP.NET to additionally sign encrypted data, preventing attackers from successfully tampering with ciphertext.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a proof-of-concept Ruby exploit for CVE-2010-3332 (MS10-070), a padding oracle vulnerability in Microsoft ASP.NET. The main file, 'aspx_po_chotext_attack.rb', implements a CBC padding oracle attack, allowing an attacker to decrypt and encrypt arbitrary ciphertexts by interacting with a vulnerable ASP.NET web application. The exploit targets a user-supplied URL (e.g., 'http://192.168.1.1/Default.aspx') and attempts to retrieve the 'Web.config' file from the server, demonstrating the ability to read sensitive files. The code includes custom modules for base64 encoding/decoding, XOR operations, and several padding verification strategies. The README provides a brief description and references the vulnerability. The exploit is a standalone script and does not belong to a larger framework. Its primary purpose is to demonstrate the impact of the padding oracle vulnerability in ASP.NET applications.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infamous zero-day vulnerability in Windows ASP.NET's handling of cryptographic errors, addressed by emergency patch MS10-070.
Older ASP.NET padding oracle vulnerability mentioned only as historical comparison to the ShareFile flaw.
An ASP.NET padding oracle information disclosure vulnerability caused by improper error handling during encryption padding verification. It can allow attackers to decrypt protected data, tamper with encrypted data, and on .NET Framework 3.5 SP1 and later retrieve contents of files within the ASP.NET application, including web.config.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.