CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
MS12-083 | Vulnerability in IP-HTTPS Component Could Allow Security Feature Bypass (2765809) | Windows Server | Important | 12-12-2012 |
Technical Information
Brief overview of the risk:
The vulnerability could allow security feature bypass if an attacker presents a revoked certificate to an IP-HTTPS server commonly used in Microsoft DirectAccess deployments. To exploit the vulnerability, an attacker must use a certificate issued from the domain for IP-HTTPS server authentication. Logging on to a system inside the organization would still require system or domain credentials.
Detailed Information on the risk:
A security feature bypass vulnerability exists in Windows due to the way the IP-HTTPS Component handles certificates. An attacker who successfully exploited this vulnerability could bypass certificate validation checks.
Further information on this exploit is available at : MS12-083
Affected Software
Windows Server 2008 R2 for x64-based SystemsWindows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for Itanium-based Systems
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
Windows Server 2012