Microsoft released a security bulletin (MS15-101) describing a .NET MVC denial of service vulnerability. This post analyzes the vulnerability in detail, starting from the theory and then providing a PoC exploit against a MVC web application developed with Visual Studio 2013.
55d8209e7983e84bd1e4c26a7391e903dbc491657d32f7b08b0c81b8bfb845bd