Beschreibung
An unspecified vulnerability was found in Microsoft .NET Framework. By exploiting this vulnerability malicious users can decrypt SSL/TLS traffic. This vulnerability can be exploited remotely via a man-in-the-middle attack.
Technical details
First of all users with TLS 1.2 enabled aren’t affected. To exploit this vulnerability attacker would first inject unencrypted data into the secure channel and then perform MiTM attack. Microsoft recommends to download and test update in controlledmanaged environments before deploying it in production environment. In case of compatibility issues this vulnerability can be mitigated via checking that server and client endpoints correctly implementing TLS RFC. For further instructions you can look at Microsoft KB3155464, listed at solution section.
Ursprüngliche Informationshinweise
CVE Liste
- CVE-2016-0149 warning
KB Liste
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com