Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
Conclusion & alert: CVE-2010-3332 is rated High Exploit Risk (73.3/100): CVSS Medium severity, with high exploitation likelihood (EPSS 83.60%, 99th percentile). Core evidence: 5 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 15292 | exploit_db | edb | 2010-10-20 | Exploit-DB ↗ |
| 15265 | exploit_db | edb | 2010-10-17 | Exploit-DB ↗ |
| 15213 | exploit_db | edb | 2010-10-06 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-12 | 85.69% | 83.60% | -2.09% |
| 2 | 2026-03-04 | 74.31% | 85.69% | +11.38% |
| 3 | 2026-03-01 | — | 74.31% | — |
Full EPSS history (42 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.4 | 2.0 | MEDIUM |
|
10.0 | 4.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
gentoo
|
high | CVE-2010-3332: 1 GLSA(s) (201206-13), 2 atom(s) (dev-lang/mono, dev-util/mono-debugger); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2010-3332 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| microsoft | .net_framework | 1.1 | cpe:2.3:a:microsoft:.net_framework:1.1:sp1:*:*:*:*:*:* |
| microsoft | .net_framework | 2.0 | cpe:2.3:a:microsoft:.net_framework:2.0:sp1:*:*:*:*:*:* |
| microsoft | .net_framework | 2.0 | cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:* |
| microsoft | .net_framework | 3.5 | cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:* |
| microsoft | .net_framework | 3.5 | cpe:2.3:a:microsoft:.net_framework:3.5:sp1:*:*:*:*:*:* |
| microsoft | .net_framework | 3.5.1 | cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:* |
| microsoft | .net_framework | 4.0 | cpe:2.3:a:microsoft:.net_framework:4.0:-:*:*:*:*:*:* |