Skip to main content

Improperly Issued Digital Certificates Spoofing Vulnerability

Last Update Date: 14 Jul 2014 Release Date: 11 Jul 2014 3336 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

National Informatics Centre (NIC) improperly issued a subordinate CA certificate, and that this subordinate CA certificate has been misused to issue SSL certificates for multiple sites including Google web properties. These SSL certificates could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against web properties. The subordinate CA certificate may also have been used to issue certificates for other, currently unknown sites, which could be subject to similar attacks.

Microsoft is updating the Certificate Trust list (CTL) for all supported releases of Microsoft Windows to remove the trust of certificates that are causing this issue.


Impact

  • Spoofing

System / Technologies affected

  • All supported releases of Microsoft Windows.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update the Certificate Trust list (CTL) through the automatic updater of revoked certificates.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link