Microsoft is currently investigating a reported vulnerability affecting ASP.NET that could allow an attacker to send a specially-formed URL request that could result in the system bypassing authentication and disclosing content.
Microsoft is working on a security update for this reported vulnerability. To aid customers in protecting their ASP.NET applications, an HTTP module has been developed that implements canonicalization best practices. By applying this module to your web server, all ASP.NET applications on the server are protected against canoncalization problems known to Microsoft as of the publication date. For more information on this reported vulnerability, visit the following Microsoft web site: http://www.microsoft.com/security/incident/aspnet.mspx