CVE-2010-3332

Exp

Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."

Published: 2010-09-22 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2010-3332 is rated High Exploit Risk (73.3/100): CVSS Medium severity, with high exploitation likelihood (EPSS 83.60%, 99th percentile). Core evidence: 5 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2010-3332

EDB-ID Source Kind Published Link
15292 exploit_db edb 2010-10-20 Exploit-DB ↗
15265 exploit_db edb 2010-10-17 Exploit-DB ↗
15213 exploit_db edb 2010-10-06 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2010-3332

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-04-12 85.69% 83.60% -2.09%
2 2026-03-04 74.31% 85.69% +11.38%
3 2026-03-01 74.31%

Full EPSS history (42 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2010-3332

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.4 2.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
10.0 4.9 [email protected]

Weakness enumeration for CVE-2010-3332

OS Trackers for CVE-2010-3332

vendor priority summary link
gentoo high CVE-2010-3332: 1 GLSA(s) (201206-13), 2 atom(s) (dev-lang/mono, dev-util/mono-debugger); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2010-3332

Affected software / configurations for CVE-2010-3332

Vendor Product Version Raw CPE
microsoft .net_framework 1.1 cpe:2.3:a:microsoft:.net_framework:1.1:sp1:*:*:*:*:*:*
microsoft .net_framework 2.0 cpe:2.3:a:microsoft:.net_framework:2.0:sp1:*:*:*:*:*:*
microsoft .net_framework 2.0 cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*
microsoft .net_framework 3.5 cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*
microsoft .net_framework 3.5 cpe:2.3:a:microsoft:.net_framework:3.5:sp1:*:*:*:*:*:*
microsoft .net_framework 3.5.1 cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*
microsoft .net_framework 4.0 cpe:2.3:a:microsoft:.net_framework:4.0:-:*:*:*:*:*:*

References for CVE-2010-3332

URL Tags
http://blogs.technet.com/b/srd/archive/2010/09/17/understanding-the-asp-net-vulnerability.aspx Vendor Advisory
http://isc.sans.edu/diary.html?storyid=9568 Third Party Advisory
http://pentonizer.com/general-programming/aspnet-poet-vulnerability-what-else-can-i-do/ Third Party Advisory
http://secunia.com/advisories/41409 Third Party Advisory
http://securitytracker.com/id?1024459 Third Party Advisory VDB Entry
http://threatpost.com/en_us/blogs/new-crypto-attack-affects-millions-aspnet-apps-091310 Third Party Advisory
http://twitter.com/thaidn/statuses/24832350146 Broken Link
http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspx Mitigation Third Party Advisory
http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryId/2799/Oracle-Padding-Vulnerability-in-ASP-NET.aspx Third Party Advisory
http://www.ekoparty.org/juliano-rizzo-2010.php Broken Link
http://www.microsoft.com/technet/security/advisory/2416728.mspx Broken Link
http://www.mono-project.com/Vulnerabilities#ASP.NET_Padding_Oracle Exploit Third Party Advisory
http://www.securityfocus.com/bid/43316 Third Party Advisory VDB Entry
http://www.theinquirer.net/inquirer/news/1732956/security-researchers-destroy-microsoft-aspnet-security Third Party Advisory
http://www.troyhunt.com/2010/09/fear-uncertainty-and-and-padding-oracle.html Exploit Third Party Advisory
http://www.vupen.com/english/advisories/2010/2429 Third Party Advisory
http://www.vupen.com/english/advisories/2010/2751 Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070 Patch Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/61898 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12365 Third Party Advisory
cvelogic Threat Intelligence