PT-2011-2853 · Microsoft · Iis+2
Published
2011-02-23
·
Updated
2011-04-21
·
CVE-2011-1068
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Azure Software Development Kit (SDK) versions 1.3.x before 1.3.20121.1237
Description
The issue is related to the improper support of cookies for maintaining state in ASP.NET applications when used with Full IIS and a Web Role. This allows remote attackers to obtain potentially sensitive information by reading an encrypted cookie and performing other steps.
Recommendations
For Microsoft Windows Azure Software Development Kit (SDK) versions 1.3.x before 1.3.20121.1237, update to version 1.3.20121.1237 or later to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asp.Net
Iis
Windows Azure Software Development Kit