Update: Microsoft Issues Out-of-Band Security Update to address ASP.NET Vulnerability--SharePoint Vulnerable to Oracle Padding Attack

Update--Microsoft issues out-of-band security update for the ASP.NET vulnerability.

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Update:
MIcrosoft's ASP.NET Security update now available:
To read the Microsoft Security Bulletin MS10-070 - Important
Vulnerability in ASP.NET Could Allow Information Disclosure (2418042) go to the Microsoft website.

From a SharePoint-related FAQ in Scott Guthrie's blog (ScottGu) entry at Microsoft titled "ASP.NET Security Update Now Available":
"Does this update work with SharePoint?"
"Yes. We have not found any issues in testing SharePoint with this security update. You should install it on SharePoint servers to ensure that they are not vulnerable."

From Microsoft TechNet webinar with Dave and Duncan on 9/28/10:
"Will SharePoint be affected?"
"It is affected but you don't need to do anything beyond applying the security update."
"Will there be a specific patch for SharePoint?"
"No."
"The products using ASP.Net will be protected after this update is installed. If you have Exchange or SP, alll you need is this update."

See also the post from the SharePoint Product team blog.

Earlier:
The Microsoft SharePoint Product Group blog has updates about the recent security vulnerability involving ASP.Net. Note the 9/22/10 update. They also offer a workaround and a warning.

If you're interested in learning more about the oracle padding attack, Paul Robichaux, Exchange expert at Windows IT Pro magazine offers a detailed article that's worth a look.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like