Microsoft .NET Framework TLS/SSL Information Disclosure Vulnerability
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
An information disclosure vulnerability exists in the TLS/SSL protocol, implemented in the encryption component of Microsoft .NET Framework. An attacker who successfully exploited this vulnerability could decrypt encrypted SSL/TLS traffic.
To exploit the vulnerability, an attacker would first have to inject unencrypted data into the secure channel and then perform a man-in-the-middle (MiTM) attack between the targeted client and a legitimate server. The update addresses the vulnerability by modifying the way that the .NET encryption component sends and receives encrypted network packets.
Impact
- Information Disclosure
System / Technologies affected
- Windows Server 2008, 2008 R2, 2012, 2012 R2
- Windows Vista, 7, 8, 8.1, RT 8.1, 10
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/library/security/MS16-065
Vulnerability Identifier
Source
Related Link
Share with