digital certificates

  1. Microsoft Security Advisory (2854544): Updates to Improve Cryptography and Digital Certificate...

    Revision Note: V1.1 (August 13, 2013): Added the 2862966 and 2862973 updates to the Available Updates and Release Notes section. Summary: Microsoft is announcing the availability of updates as part of ongoing efforts to improve cryptography and digital certificate handling in Windows. Microsoft...
  2. Microsoft Security Advisory (2854544): Update to Improve Cryptography and Digital Certificate...

    Revision Note: V1.0 (June 11, 2013): Advisory published. Summary: Microsoft is announcing the availability of an update as part of ongoing efforts to improve cryptography and digital certificate handling in Windows. Over the course of months, Microsoft will continue to announce additional...
  3. Microsoft Security Advisory (2728973): Unauthorized Digital Certificates Could Allow Spoofing...

    Revision Note: V1.2 (September 5, 2012): Corrected the common name for the "CN=Microsoft Online Svcs BPOS APAC CA4" certificate issued by Microsoft Services PCA. Summary: Microsoft is aware of Microsoft certificate authorities that are outside our recommended secure storage practices. Upon a...
  4. Microsoft Security Advisory (2749655): Compatibility Issues Affecting Signed Microsoft...

    Revision Note: V2.0 (December 11, 2012): Added the KB2687627 and KB2687497 updates described in MS12-043, the KB2687501 and KB2687510 updates described in MS12-057, the KB2687508 update described in MS12-059, and the KB2726929 update described in MS12-060 to the list of available rereleases...
  5. Microsoft Security Advisory (2854544): Update to Improve Cryptography and Digital Certificate...

    Revision Note: V1.0 (June 11, 2013): Advisory published. Summary: Microsoft is announcing the availability of an update as part of ongoing efforts to improve cryptography and digital certificate handling in Windows. Over the course of months, Microsoft will continue to announce additional...
  6. June 2013 Security Bulletin Webcast, Q&A, and Slide Deck

    Today we’re publishing the Link Removed. We fielded three questions during the webcast, with specific questions focusing primarily on Windows Print Spooler (MS13-050), Microsoft Office (MS13-051), and the security advisory addressing digital certificates (SA2854544). There was one...
  7. Improved cryptography infrastructure and the June 2013 bulletins

    It was just over one year ago, May 28, 2012, to be exact, that I transitioned from running active MSRC cases and writing bulletins to my current role managing software security incidents. A lot has changed in that year - and I’ve dealt with some interesting issues during my tenure - but...
  8. Microsoft Security Advisory (2854544): Update to Improve Cryptography and Digital Certificate Handli

    Revision Note: V1.0 (June 11, 2013): Advisory published. Summary: Microsoft is announcing the availability of an update as part of ongoing efforts to improve cryptography and digital certificate handling in Windows. Over the course of months, Microsoft will continue to announce...
  9. Microsoft Security Advisory (2749655): Compatibility Issues Affecting Signed Microsoft Binaries - Ve

    Revision Note: V1.0 (October 9, 2012): Advisory published. Summary: Microsoft is aware of an issue involving specific digital certificates that were generated by Microsoft without proper timestamp attributes. These digital certificates were later used to sign some Microsoft core...
  10. Gadgets, certificate housekeeping and the July 2012 bulletins

    Before we dive into the July security updates, let’s change up the normal order and take a look at the two Security Advisories we are releasing today. One takes an exciting step into the future, while the other prepares us to take an equally important step away from the past. Security...
  11. Microsoft Security Advisory (2728973): Unauthorized Digital Certificates Could Allow Spoofing - Vers

    Revision Note: V1.0 (July 10, 2012): Advisory published. Summary: Microsoft is aware of Microsoft certificate authorities that are outside our recommended secure storage practices. Upon a routine review, we are placing these certificates in the Untrusted Certificate Store, and...
  12. Microsoft Security Advisory (2718704): Unauthorized Digital Certificates Could Allow Spoofing - Vers

    Revision Note: V1.0 (June 3, 2012): Advisory published. Summary: Microsoft is aware of active attacks using three unauthorized digital certificates derived by a Microsoft Certificate Authority. An unauthorized certificate could be used to spoof content, perform phishing attacks, or...
  13. TA12-156A: Microsoft Windows Unauthorized Digital Certificates

    Syndicated from the United States Security Readiness Team (US-CERT). Link Removed - Invalid URL
  14. Unauthorized digital certificates could allow spoofing

    Provides a link to Microsoft Security Advisory (2718704): Unauthorized digital certificates could allow spoofing. Link Removed
  15. Microsoft Security Advisory (2718704): Unauthorized Digital Certificates Could Allow Spoofing - Vers

    Revision Note: V1.0 (June 3, 2012): Advisory published. Summary: Microsoft is aware of active attacks using three unauthorized digital certificates derived by a Microsoft Certificate Authority. An unauthorized certificate could be used to spoof content, perform phishing attacks, or...
  16. Microsoft Security Advisory (2641690): Fraudulent Digital Certificates Could Allow Spoofing - Versio

    Revision Note: V2.0 (November 16, 2011): Revised to announce the rerelease of the KB2641690 update. See the Update FAQ in this advisory for more information. Also, added link to Microsoft Knowledge Base Article 2641690 under Known Issues in the Executive Summary. Summary: Microsoft is...
  17. Microsoft Security Advisory (2641690): Fraudulent Digital Certificates Could Allow Spoofing - Versio

    Revision Note: V1.0 (November 10, 2011): Advisory published. Summary: Microsoft is aware that DigiCert Sdn. Bhd, a Malaysian subordinate certification authority (CA) under Entrust and GTE CyberTrust, has issued 22 certificates with weak 512 bit keys. These weak encryption keys, when...
  18. Microsoft Security Advisory (2524375): Fraudulent Digital Certificates Could Allow Spoofing - Versio

    Revision Note: V5.0 (July 6, 2011): Announced the release of an update for Zune HD devices and moved Zune devices to the Non-Affected Devices table. Summary: Microsoft is aware of nine fraudulent digital certificates issued by Comodo, a certification authority present in the Trusted...
  19. Microsoft Security Advisory (2607712): Fraudulent Digital Certificates Could Allow Spoofing - Versio

    Revision Note: V3.0 (September 6, 2011): Revised to announce the release of an update that addresses this issue. Summary: Microsoft is aware of active attacks using at least one fraudulent digital certificate issued by DigiNotar, a certification authority present in the Trusted Root...
  20. Microsoft Security Advisory: Fraudulent digital certificates could allow spoofing

    Provides a link to Microsoft Security Advisory (2607712): Fraudulent digital certificates could allow spoofing. Link Removed