Skip to main content

Windows Phone PEAP-MS-CHAPv2 Authentication Protocol Vulnerability

Last Update Date: 5 Aug 2013 11:32 Release Date: 5 Aug 2013 3689 Views

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

A vulnerability has been identified in the PEAP-MS-CHAPv2 authentication protocol used by Windows Phone, which can be exploited by remote user can obtain authentication information.

The Protected Extensible Authentication Protocol with Microsoft Challenge Handshake Authentication Protocol version 2 (PEAP-MS-CHAPv2) Wi-Fi authentication protocol used by Windows Phones for WPA2 wireless authentication contains a known cryptographic weakness. A remote user can exploit this weakness to obtain the target user's domain credentials and use those credentials to access network resources acting as the target user.


Impact

  • Information Disclosure

System / Technologies affected

  • Windows Phone 8
  • Windows Phone 7.8

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link