CERT-In Vulnerability Note
CIVN-2015-0282
Microsoft Windows IPSec Denial of Service Vulnerability
Original Issue Date:November 12, 2015
Severity Rating: MEDIUM
Software Affected
- Windows 8 for 32-bit Systems
- Windows 8 for x64-based Systems
- Windows 8.1 for 32-bit Systems
- Windows 8.1 for x64-based Systems
- Windows Server 2012
- Windows Server 2012 R2
- Windows RT and Windows RT 8.1
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2 (Server Core installation)
Overview
A vulnerability has been reported in the IPsec service of Microsoft Windows that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
Description
This vulnerability exists in Microsoft windows due to improper handling of encryption negotiation by the Internet Protocol Security (IPSec) service. An authenticated, remote attacker could exploit this vulnerability by connecting a malicious application to the targeted system.
Successful exploitation of this vulnerability could cause the system to stop responding, resulting in a denial of service (DoS) condition.
Solution
Apply appropriate updates as mentioned in the Microsoft Security Bulletin
MS15-120
Vendor Information
Microsoft
https://technet.microsoft.com/library/security/ms15-120
References
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=41867
Symantec
http://www.symantec.com/security_response/vulnerability.jsp?bid=77481
Security Tracker
http://securitytracker.com/id/1034123
CVE Name
CVE-2015-6111
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|