• News/
  • https://www.bleepingcomputer.com/news/security/microsoft-says-attackers-use-exposed-aspnet-keys-to-deploy-malware/

Microsoft says attackers use exposed ASP.NET keys to deploy malware

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 6, 2025
·
Updated

Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online. As Microsoft Threat Intelligence experts recently discovered, some developers use ASP.NET validationKey and decryptionKey keys (designed to protect ViewState from tampering and information disclosure) found on code documentation and repository platforms in their own software. However, threat actors also use machine keys from publicly available sources in code injection attacks to create malicious ViewStates (used by ASP.NET Web Forms to control state and preserve pages) by attaching crafted message authentication code (MAC). When loading the ViewStates sent via POST requests, the ASP.NET Runtime on the targeted server decrypts and validates the attackers' maliciously crafted ViewState data because it uses the right keys, loads it into the worker process memory, and executes it. This grants them remote code execution (RCE) on the targeted IIS web servers, allowing them to deploy additional malicious payloads. In one instance, observed in December 2024, an unattributed attacker used a publicly known machine key to deliver the Godzilla post-exploitation framework, which features malicious command execution and shellcode injection capabilities, to a targeted Internet Information Services (IIS) web server. "Microsoft has since identified over 3,000 publicly disclosed keys that could be used for these types of attacks, which are called ViewState...

Read full article

Affected Software

4 affected components
Microsoft ASP.NET
Microsoft Internet Information Services (IIS)
Microsoft ASP.NET
Microsoft IIS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how attackers are exploiting exposed ASP.NET machine keys to deploy malware through ViewState code injection attacks.

2

What security implications are discussed in the article?

The article highlights the risk of malware deployment due to poorly secured ASP.NET machine keys, emphasizing the need for better key management.

3

What products or software are affected by this security issue?

The affected products include Microsoft ASP.NET and Internet Information Services (IIS).

4

What type of attack is being utilized by the attackers mentioned in the article?

Attackers are utilizing ViewState code injection attacks to exploit exposed ASP.NET machine keys.

5

What prevention measures does Microsoft recommend to mitigate this issue?

Microsoft recommends securing ASP.NET machine keys and following best practices for key management to prevent unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203