CERT-In Vulnerability Note
CIVN-2012-0119
Microsoft Windows Revoke Certificate Bypass Vulnerability
Original Issue Date:December 12, 2012
Severity Rating: MEDIUM
Systems Affected
- Windows Server 2008 R2 for x64-based Systems
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for Itanium-based Systems
- Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
- Windows Server 2012
- Windows Server 2008 R2 for x64-based Systems
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2012
Overview
A vulnerability has been reported in IP-HTTPS server in Windows Server, due to which remote attackers could bypass access restrictions via a revoked certificate.
Description
IP over HTTPS (IP-HTTPS) is a protocol which helps establish secure IP tunnels using secure HTTP connections. It is commonly used in Microsoft DirectAccess deployments .
This vulnerability occurs due to Windows inability to properly check the validity of certificates. A remote attacker could exploit this vulnerability to bypass security access restrictions.
Workaround
- Disable the domain computer accounts associated with revoked client certificates.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS12-083
Vendor Information
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-083
References
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-083
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=27535
Security Tracker
http://securitytracker.com/id/1027860
CVE Name
CVE-2012-2549
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|