• News/
  • https://www.darkreading.com/remote-workforce/microsoft-public-asp-net-keys-web-server-rce

Microsoft: Thousands of Public ASP.NET Keys Allow Web Server RCE

Dark Reading
·
Tara Seals, Managing Editor, News
·
Published Feb 7, 2025
·
Updated

NEWS BRIEF Website developers are unwittingly putting their companies at risk by incorporating publicly disclosed ASP.NET machine keys from code documentation and repositories into their applications, Microsoft is warning. The tech giant has issued an alert on the insecure practice, after observing threat actors in December using a static, known ASP.NET machine key to deploy the Godzilla post-exploitation cyberattack framework, known for stomping all over corporate environments. The attack vector involves manipulating ViewState, which represents the state of a webpage when it was last processed on the server. If threat actors can get ahold of ASP.NET keys, they can craft a malicious ViewState, send it to a targeted website via a POST request to be loaded, and can thus compromise the environment via code injection. "Once it's processed by ASP.NET Runtime on the targeted server, the ViewState is decrypted and validated successfully because the right keys are used," a Microsoft post on the concern explained. "The malicious code is then loaded into the worker process memory and executed, providing the threat actor remote code execution capabilities on the target IIS Web server." Microsoft has uncovered at least 3,000 publicly disclosed keys that could be used for these types of attacks, which lowers the bar for exploitation significantly. "Whereas many previously known ViewState code injection attacks used compromised or stolen keys that are often sold on Dark Web forums, these p...

Read full article

Affected Software

3 affected components
Microsoft ASP.NET
Microsoft IIS
Microsoft ASP.NET
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how developers are endangering their applications by using publicly disclosed ASP.NET machine keys.

2

What security implications are discussed?

The use of exposed ASP.NET keys can lead to remote code execution (RCE) vulnerabilities in web applications.

3

What products or software are affected?

The affected software includes Microsoft ASP.NET and Microsoft IIS.

4

How are developers unwittingly exposing their applications?

Developers are incorporating publicly available ASP.NET machine keys from code documentation and repositories without realizing the risks.

5

What does Microsoft recommend to mitigate this issue?

Microsoft advises developers to avoid using publicly disclosed keys and to implement secure practices for managing machine keys.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203