How is that a security hole? It's actually .Net having a bad default configuration for ASP.Net MVC, a lot of us made this same mistake when doing our first MVC projects. It's not actually exposing anything dangerous (in fact it's hiding the actual error like it should do).
The actual error will be something like this:
http://stackoverflow.com/questions/5967103/a-potentially-dan...
It's .Net disallowing at the root level and if you don't know about it, you can't code for it.
Or am I missing something? Given it's Troy Hunt who's usually quite knowledgeable about this stuff, I'm confused?