PT-2002-2546 · Microsoft · Internet Explorer

Publicado

2002-12-31

·

Atualizado

2021-07-23

·

CVE-2002-1824

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer version 6.0
Description The issue concerns the handling of an expired CA-CERT in a web server's certificate chain during an SSL/TLS handshake. It may allow attackers to perform a man-in-the-middle attack by not prompting the user before searching for and finding a newer certificate.
Recommendations For Microsoft Internet Explorer version 6.0, consider disabling the automatic search for newer certificates during the SSL/TLS handshake as a temporary workaround until a more permanent solution is available. Restrict access to sensitive information when using this version of Internet Explorer to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1824

Produtos afetados

Internet Explorer