This article is 100% wrong. The IV is not a secret, must be know for decryption. In-fact counter mode simply picks a starting IV and increments. Allowing the attacker to manipulate the IV or reuse of an IV can be problematic, but a guessable IV is of NO HELP to an attacker
Totally irresponsible journalism. This is not all or .NET or even a tiny fraction. It is one control that will be rapidly patched.
This allows the end user to decrypt their own "encrypted" cookie, not an attacker. At best, if the web app writers were stupid and put truly exploitable data in the cookie, they'd be effected.
It is horrible that MS missed this, but calling .NET broken is probably actionable libel.