CERT-In Vulnerability Note
CIVN-2013-0204
Microsoft Windows X.509 Certificate Processing Denial of Service Vulnerability
Original Issue Date:November 13, 2013
Severity Rating: HIGH
Systems Affected
- Windows XP SP 3
- Windows XP Professional x64 Edition SP 2
- Windows Server 2003 SP 2, x64 Edition SP 2 and SP2 for Itanium-based Systems
- Windows Vista SP 2 and x64 Edition SP 2
- Windows Server 2008 SP2 for 32-bit Systems , x64-based Systems and Itanium-based Systems
- Windows 7 SP1 for 32-bit Systems and x64-based Systems
- Windows Server 2008 R2 SP 1 for x64-based Systems and Itanium-based Systems
- Windows 8 for 32-bit Systems and x64-based Systems
- Windows 8.1 for 32-bit Systems and x64-based Systems
- Windows Server 2012
- Windows Server 2012 R2
- Windows RT
- Windows RT 8.1
- Windows Server 2008 SP 2 for 32-bit Systems (Server Core installation), x64-based Systems (Server Core installation)
- Windows Server 2008 R2 for x64-based Systems SP 1 (Server Core installation)
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2 (Server Core installation)
Overview
A vulnerability has been reported in Microsoft Windows that could allow a remote attacker to cause denial of service conditions on the targeted system.
Description
This vulnerability exists in Microsoft Windows due to improper handling of crafted X.509 certificates by the affected device.
A remote attacker could exploit this vulnerability by sending a crafted X.509 certificate to cause the web service that validates X.509 certificates become unresponsive, resulting in denial of service (DoS) conditions.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS13-095
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/security/bulletin/ms13-095
References
SecurityTracker
http://securitytracker.com/id/1029329
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=31622
Secunia
http://secunia.com/advisories/55629/
CVE Name
CVE-2013-3869
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|