All the latest UK technology news, reviews and analysis

Microsoft readies out-of-cycle ASP.NET patch

by Dave Neal

28 Sep 2010

Be the first to comment

  • Tweet this
Microsoft

Microsoft is preparing to release an out-of-band security fix for the ASP.NET flaw reported earlier this month.

The company admitted to the problem in a security advisory on 17 September, in which it suggested a workaround that companies should apply "immediately".

Microsoft will now post an out-of-cycle patch for the vulnerability, given its critical nature.

The flaw exists in all versions of ASP.NET 2, and Microsoft recommends that customers apply the patch to prevent attackers compromising ASP.NET applications.

Wolfgang Kandek, chief technology officer at Qualys, echoed this advice, urging companies to install the patch as soon as it becomes available.

"IT administrators should first focus on web servers that do not have the workarounds implemented," he added.

The flaw gives attackers access to information found in the web.config file, which could be sensitive, and allows for the interception of other material sent to any client machine.

Microsoft updated its reference pages about the flaw at the end of last week, and said that it is aware of a number of "limited, active attacks".

Affected software includes Windows XP, including SP3 and Professional, Windows Server 2003 and 2008, Windows Vista and Windows 7.

Microsoft's Security Bulletin Advance Notification for September 2010 warned that the ASP.NET flaw can lead to information disclosure.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

37%

0%

11%

52%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Availability & Capacity Lead

About Us WorldPay provides a globally connected, locally...

Change & Configuration Administrator

About Us WorldPay provides a globally connected, locally...

SQL Server Developer - SSIS - Zurich

SQL Server Developer - Our client, an international...

IT Technical Service Delivery Manager / ITIL / Reigate - 65K

IT Technical Service Delivery Manager / ITIL / Reigate...

To send to more than one email address, simply separate each address with a comma.