Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.801109
Categoría:Windows
Título:Microsoft IE CA SSL Certificate Security Bypass Vulnerability (Oct 2009)
Resumen:Internet Explorer is prone to a security bypass vulnerability.;; This VT has been deprecated and replaced by the VT 'Microsoft Windows CryptoAPI X.509 Spoofing Vulnerabilities (974571)' (OID: 1.3.6.1.4.1.25623.1.0.900876).
Descripción:Summary:
Internet Explorer is prone to a security bypass vulnerability.

This VT has been deprecated and replaced by the VT 'Microsoft Windows CryptoAPI X.509 Spoofing Vulnerabilities (974571)' (OID: 1.3.6.1.4.1.25623.1.0.900876).

Vulnerability Insight:
Microsoft Internet Explorer fails to properly validate '\0' character in the
domain name in a signed CA certificate, allowing attackers to substitute
malicious SSL certificates for trusted ones.

Vulnerability Impact:
Successful exploitation will allow attackers to perform man-in-the-middle
attacks or impersonate trusted servers, which will aid in further attack.

Affected Software/OS:
Microsoft IE version 6.x/7.x/8.x.

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-2510
BugTraq ID: 36475
http://www.securityfocus.com/bid/36475
Cert/CC Advisory: TA09-286A
http://www.us-cert.gov/cas/techalerts/TA09-286A.html
http://www.networkworld.com/news/2009/073009-more-holes-found-in-webs.html
http://www.networkworld.com/news/2009/091709-microsoft-ie-security-hole.html
http://www.wired.com/threatlevel/2009/07/kaminsky/
Microsoft Security Bulletin: MS09-056
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-056
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5842
CopyrightCopyright (C) 2009 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.