PT-2012-4093 · Microsoft · Windows Server 2008 R2+1

Published

2012-12-12

·

Updated

2020-09-28

·

CVE-2012-2549

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Windows Server versions 2008 R2 through 2012
Description The issue arises from the IP-HTTPS server's failure to properly validate certificates. This allows remote attackers to bypass intended access restrictions by using a revoked certificate.
Recommendations For Windows Server 2008 R2 and R2 SP1, update the certificate validation mechanism to properly check for revoked certificates. For Windows Server 2012, ensure that the IP-HTTPS server is configured to validate certificates correctly, preventing the use of revoked certificates.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2549

Affected Products

Windows Server 2008 R2
Windows Server 2012