PT-2011-2853 · Microsoft · Iis+2

Published

2011-02-23

·

Updated

2011-04-21

·

CVE-2011-1068

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows Azure Software Development Kit (SDK) versions 1.3.x before 1.3.20121.1237
Description The issue is related to the improper support of cookies for maintaining state in ASP.NET applications when used with Full IIS and a Web Role. This allows remote attackers to obtain potentially sensitive information by reading an encrypted cookie and performing other steps.
Recommendations For Microsoft Windows Azure Software Development Kit (SDK) versions 1.3.x before 1.3.20121.1237, update to version 1.3.20121.1237 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1068

Affected Products

Asp.Net
Iis
Windows Azure Software Development Kit