Microsoft Windows Includes Fraudulent Digital Certificates Vulnerability
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
A vulnerability was identified in Microsoft Windows. One fraudulent digital certificate issued by TURKTRUST Inc., which is a CA present in the Trusted Root Certification Authorities Store, could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks.
TURKTRUST Inc. incorrectly created two subsidiary CAs (*.EGO.GOV.TR and e-islem.kktcmerkezbankasi.org). The *.EGO.GOV.TR subsidiary CA was then used to issue a fraudulent digital certificate to *.google.com. This fraudulent certificate could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against several Google web properties.
Impact
- Spoofing
System / Technologies affected
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
- Windows 8
- Windows Server 2012
- Windows RT
- Windows Phone 8
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (KB2677070), which is available via automatic updater.
http://support.microsoft.com/kb/2677070
http://technet.microsoft.com/en-us/security/advisory/2798897
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with