PT-2012-3612 · Microsoft · Windows Server 2008+5

Published

2012-07-10

·

Updated

2023-12-07

·

CVE-2012-1870

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows XP SP2 and SP3 Microsoft Windows Server 2003 SP2 Microsoft Windows Vista SP2 Microsoft Windows Server 2008 SP2, R2, and R2 SP1 Microsoft Windows 7 Gold and SP1
Description The issue allows remote web servers to obtain plaintext data by triggering multiple requests to a third-party HTTPS server and sniffing the network during the resulting HTTPS session. This is an information disclosure issue that affects the TLS encryption protocol itself, allowing the decryption of encrypted TLS traffic. It primarily impacts HTTPS traffic, as the browser is the primary attack vector, and all web traffic served via HTTPS or mixed content HTTP/HTTPS is affected.
Recommendations For Microsoft Windows XP SP2 and SP3, consider disabling TLS protocol until a patch is available. For Microsoft Windows Server 2003 SP2, restrict access to HTTPS traffic to minimize the risk of exploitation. For Microsoft Windows Vista SP2, avoid using mixed content HTTP/HTTPS in web traffic until the issue is resolved. For Microsoft Windows Server 2008 SP2, R2, and R2 SP1, consider implementing additional security measures to protect HTTPS traffic. For Microsoft Windows 7 Gold and SP1, restrict access to the TLS encryption protocol to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1870

Affected Products

Windows
Windows 7
Windows Server 2003
Windows Server 2008
Windows Vista
Windows Xp