Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.11145
Category:Windows : Microsoft Bulletins
Title:Certificate Validation Flaw Could Enable Identity Spoofing (Q328145)
Summary:Hotfix to fix Certificate Validation Flaw (Q329115); is not installed.
Description:Summary:
Hotfix to fix Certificate Validation Flaw (Q329115)
is not installed.

Vulnerability Insight:
The vulnerability could enable an attacker who had a valid end-entity certificate to issue a
subordinate certificate that, although bogus, would nevertheless pass validation. Because
CryptoAPI is used by a wide range of applications, this could enable a variety of identity
spoofing attacks.

Vulnerability Impact:
Identity spoofing.

Affected Software/OS:
- Microsoft Windows 98

- Microsoft Windows 98 (Second Edition)

- Microsoft Windows Me

- Microsoft Windows NT 4.0

- Microsoft Windows NT 4.0 (Terminal Server Edition)

- Microsoft Windows 2000

- Microsoft Windows XP

- Microsoft Office for Mac

- Microsoft Internet Explorer for Mac

- Microsoft Outlook Express for Mac

Solution:
The vendor has released updates, please see the references for more information.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-1183
BugTraq ID: 5410
http://www.securityfocus.com/bid/5410
Microsoft Security Bulletin: MS02-050
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-050
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1059
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1455
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2108
XForce ISS Database: ssl-ca-certificate-spoofing(9776)
https://exchange.xforce.ibmcloud.com/vulnerabilities/9776
Common Vulnerability Exposure (CVE) ID: CVE-2002-0862
Bugtraq: 20020805 IE SSL Vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=102866120821995&w=2
Bugtraq: 20020812 IE SSL Exploit (Google Search)
http://marc.info/?l=bugtraq&m=102918200405308&w=2
Bugtraq: 20020819 Insufficient Verification of Client Certificates in IIS 5.0 pre sp3 (Google Search)
http://marc.info/?l=bugtraq&m=102976967730450&w=2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1056
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1332
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2671
CopyrightCopyright (C) 2002 SECNAP Network Security, LLC

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.