No fix at the moment, but Microsoft reported an ASP.NET vulnerability yesterday:

http://www.microsoft.com/security/incident/aspnet.mspx

It deals with the canonicalization of files and a hacker's ability to play with the URL to get at files they shouldn't. There are safeguards to protect yourself in the meantime. Check out KB article 887459:

http://support.microsoft.com/?kbid=887459