Jump to content


Photo

Microsoft Vulnerability in SSL/TLS


  • Please log in to reply
No replies to this topic

#1 Chachazz

Chachazz

    Is GSF inventory

  • General Admin
  • 33,517 posts

Posted 28 September 2011 - 10:30 PM

Microsoft Security Advisory (2588513)
Vulnerability in SSL/TLS Could Allow Information Disclosure


Microsoft is aware of detailed information that has been published describing a new method to exploit a vulnerability in SSL 3.0 and TLS 1.0, affecting the Windows operating system. This vulnerability affects the protocol itself and is not specific to the Windows operating system. This is an information disclosure vulnerability that allows the decryption of encrypted SSL/TLS traffic. This vulnerability primarily impacts HTTPS traffic, since the browser is the primary attack vector, and all web traffic served via HTTPS or mixed content HTTP/HTTPS is affected. We are not aware of a way to exploit this vulnerability in other protocols or components and we are not aware of attacks that try to use the reported vulnerability at this time. Considering the attack scenario, this vulnerability is not considered high risk to customers.

We are actively working with partners in our Microsoft Active Protections Program (MAPP) to provide information that they can use to provide broader protections to customers.

Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.

Mitigating Factors:
The attack must make several hundred HTTPS requests before the attack could be successful.
TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected.

http://technet.micro...dvisory/2588513

This is the Exploit in question:

http://www.imperialv...meandbeast.html


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users