As promised, Microsoft today delivered an emergency patch for a Windows Web server flaw that is being actively exploited by hackers.
The fix addresses a vulnerability in ASP.Net's encryption that attackers could abuse to access Web applications with full administrator rights; decrypt session cookies or other encrypted data on a remote server; and access and snatch files from sites or Web applications.
|