Skip to main content

Microsoft .NET Framework TLS/SSL Information Disclosure Vulnerability

Last Update Date: 12 May 2016 Release Date: 11 May 2016 3895 Views

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

An information disclosure vulnerability exists in the TLS/SSL protocol, implemented in the encryption component of Microsoft .NET Framework. An attacker who successfully exploited this vulnerability could decrypt encrypted SSL/TLS traffic.

 

To exploit the vulnerability, an attacker would first have to inject unencrypted data into the secure channel and then perform a man-in-the-middle (MiTM) attack between the targeted client and a legitimate server. The update addresses the vulnerability by modifying the way that the .NET encryption component sends and receives encrypted network packets.


Impact

  • Information Disclosure

System / Technologies affected

  • Windows Server 2008, 2008 R2, 2012, 2012 R2
  • Windows Vista, 7, 8, 8.1, RT 8.1, 10

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link