Generic Padding Oracle
- Risk:
High
- Type:
- Active
- CWE:
- CWE-209
- Summary
By manipulating the padding on an encrypted string, an attacker is able to generate an error message that indicates a likely ‘padding oracle’ vulnerability. Such a vulnerability can affect any application or framework that uses encryption improperly, such as some versions of ASP.net, Java Server Faces, and Mono. An attacker may exploit this issue to decrypt data and recover encryption keys, potentially viewing and modifying confidential data. This rule should detect the MS10-070 padding oracle vulnerability in ASP.net if CustomErrors are enabled for that.
- Solution
Update the affected server software, or modify the scripts so that they properly validate encrypted data before attempting decryption.
- References
https://learn.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070
https://www.mono-project.com/docs/about-mono/vulnerabilities/
Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive
Fake Microsoft Teams installers push Oyster malware via malvertising
EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations
UNC1549 Hacks 34 Devices in 11 Telecom Firms via LinkedIn Job Lures and MINIBIKE Malware
Windows 11 KB5065789 update released with 41 changes and fixes
Microsoft now enforces MFA on Azure Portal sign-ins for all tenants
Fake Madgicx Plus and SocialMetrics Extensions Are Hijacking Meta Business Accounts
Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More
Microsoft will offer free Windows 10 extended security updates in Europe
CVE-2025-4008 Smartbedded Meteobridge Command Injection Vulnerability
CVE-2025-21043 Samsung Mobile Devices Out-of-Bounds Write Vulnerability
CVE-2015-7755 Juniper ScreenOS Improper Authentication Vulnerability
CVE-2017-1000353 Jenkins Remote Code Execution Vulnerability
CVE-2021-21311 Adminer Server-Side Request Forgery Vulnerability
CVE-2025-10035 Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
CVE-2025-59689 Libraesva Email Security Gateway Command Injection Vulnerability
CVE-2025-32463 Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
InformationalInformation Disclosure - Suspicious Comments
InformationalRe-examine Cache-control Directives
Free online web security scanner