MS12-083 - Important : Vulnerability in IP-HTTPS Component Could Allow Security Feature Bypass (2765

Discussion in 'Security Alerts' started by News, Dec 11, 2012.

  1. News

    News Extraordinary Robot
    News Feed

    Joined:
    Jun 27, 2006
    Messages:
    26,189
    Likes Received:
    20
    Severity Rating: Important
    Revision Note: V1.0 (December 11, 2012): Bulletin published.
    Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow security feature bypass if an attacker presents a revoked certificate to an IP-HTTPS server commonly used in Microsoft DirectAccess deployments. To exploit the vulnerability, an attacker must use a certificate issued from the domain for IP-HTTPS server authentication. Logging on to a system inside the organization would still require system or domain credentials.

    More...
     

Share This Page

Loading...