Microsoft: Thousands of Public ASP.NET Keys Allow Web Server RCE
ID: a40182af-77da-5c6e-9533-f8036626e6af
STIX ID: report--a40182af-77da-5c6e-9533-f8036626e6af
Feed Name: Dark Reading
Date Published: 2025-02-07
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Microsoft warns that developers are importing publicly disclosed ASP.NET machine keys from documentation and code repositories, enabling attackers to craft malicious ViewState payloads that bypass validation and execute code in IIS worker processes. Microsoft observed threat actors in December using a static known key with the Godzilla post‑exploitation framework and identified roughly 3,000 publicly disclosed keys; organizations are advised to stop copying public keys and to rotate machine keys regularly to mitigate remote code execution risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
