Microsoft warns hackers have a new and devious way of distributing malware




  • ViewState code injection attacks can lead to remote code execution, Microsoft warned
  • Many devs are not generating their own machine keys for ViewState
  • There are thousands of publicly available keys cybercriminals can use

Cybercriminals are abusing a weakness in ASP.NET websites to remotely execute malicious code, according to Microsoft’s Threat Intelligence team, which has published an in-depth analysis on the new method.

In the article, Microsoft explained threat actors were injecting malicious code through a method called ViewState code injection attacks.

https://cdn.mos.cms.futurecdn.net/39RwSYL9EVNfYdyohDHBgS-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img