Improperly Issued Digital Certificates Spoofing Vulnerability
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
National Informatics Centre (NIC) improperly issued a subordinate CA certificate, and that this subordinate CA certificate has been misused to issue SSL certificates for multiple sites including Google web properties. These SSL certificates could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against web properties. The subordinate CA certificate may also have been used to issue certificates for other, currently unknown sites, which could be subject to similar attacks.
Microsoft is updating the Certificate Trust list (CTL) for all supported releases of Microsoft Windows to remove the trust of certificates that are causing this issue.
Impact
- Spoofing
System / Technologies affected
- All supported releases of Microsoft Windows.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update the Certificate Trust list (CTL) through the automatic updater of revoked certificates.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with