***Update: Today Microsoft is releasing as out-of-band security update to address this issues.
– SharePoint Team Blog Announcement – http://sharepointben/s.msdn.com/b/sharepoint/
I’m sure by now all of you have heard about the ASP.NET security vulnerability and there are plenty of references out there about it and how to fix it so I’m not going to go into much detail here. The key point is yes, it effects WSS 2.0, SharePoint 2007 (WSS 3.0 and MOSS) and SharePoint 2010 (Foundation and Server).
The best references I have found so far, and I will refer you to rather than writing it all up myself are”:
1. The Microsoft SharePoint Team Blog, this is where the fixes are documented that you can put in place until a patch is released.
2. Scott Guthrie’s Blog, this contains a very good list of FAQs about the vulnerability.