PT-2012-4093 · Microsoft · Windows Server 2008 R2+1
Published
2012-12-12
·
Updated
2020-09-28
·
CVE-2012-2549
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Windows Server versions 2008 R2 through 2012
Description
The issue arises from the IP-HTTPS server's failure to properly validate certificates. This allows remote attackers to bypass intended access restrictions by using a revoked certificate.
Recommendations
For Windows Server 2008 R2 and R2 SP1, update the certificate validation mechanism to properly check for revoked certificates.
For Windows Server 2012, ensure that the IP-HTTPS server is configured to validate certificates correctly, preventing the use of revoked certificates.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Server 2008 R2
Windows Server 2012