Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.11145
Categoría:Windows : Microsoft Bulletins
Título:Certificate Validation Flaw Could Enable Identity Spoofing (Q328145)
Resumen:Hotfix to fix Certificate Validation Flaw (Q329115); is not installed.
Descripción:Summary:
Hotfix to fix Certificate Validation Flaw (Q329115)
is not installed.

Vulnerability Insight:
The vulnerability could enable an attacker who had a valid end-entity certificate to issue a
subordinate certificate that, although bogus, would nevertheless pass validation. Because
CryptoAPI is used by a wide range of applications, this could enable a variety of identity
spoofing attacks.

Vulnerability Impact:
Identity spoofing.

Affected Software/OS:
- Microsoft Windows 98

- Microsoft Windows 98 (Second Edition)

- Microsoft Windows Me

- Microsoft Windows NT 4.0

- Microsoft Windows NT 4.0 (Terminal Server Edition)

- Microsoft Windows 2000

- Microsoft Windows XP

- Microsoft Office for Mac

- Microsoft Internet Explorer for Mac

- Microsoft Outlook Express for Mac

Solution:
The vendor has released updates, please see the references for more information.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: BugTraq ID: 5410
Common Vulnerability Exposure (CVE) ID: CVE-2002-1183
http://www.securityfocus.com/bid/5410
Microsoft Security Bulletin: MS02-050
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-050
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1059
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1455
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2108
XForce ISS Database: ssl-ca-certificate-spoofing(9776)
https://exchange.xforce.ibmcloud.com/vulnerabilities/9776
Common Vulnerability Exposure (CVE) ID: CVE-2002-0862
Bugtraq: 20020805 IE SSL Vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=102866120821995&w=2
Bugtraq: 20020812 IE SSL Exploit (Google Search)
http://marc.info/?l=bugtraq&m=102918200405308&w=2
Bugtraq: 20020819 Insufficient Verification of Client Certificates in IIS 5.0 pre sp3 (Google Search)
http://marc.info/?l=bugtraq&m=102976967730450&w=2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1056
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1332
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2671
CopyrightCopyright (C) 2002 SECNAP Network Security, LLC

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.