Windows Phone PEAP-MS-CHAPv2 Authentication Protocol Vulnerability
RISK: Medium Risk
TYPE: Operating Systems - Mobile & Apps
A vulnerability has been identified in the PEAP-MS-CHAPv2 authentication protocol used by Windows Phone, which can be exploited by remote user can obtain authentication information.
The Protected Extensible Authentication Protocol with Microsoft Challenge Handshake Authentication Protocol version 2 (PEAP-MS-CHAPv2) Wi-Fi authentication protocol used by Windows Phones for WPA2 wireless authentication contains a known cryptographic weakness. A remote user can exploit this weakness to obtain the target user's domain credentials and use those credentials to access network resources acting as the target user.
Impact
- Information Disclosure
System / Technologies affected
- Windows Phone 8
- Windows Phone 7.8
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Microsoft has described configuration changes for the wireless access points and Windows Phone 8 devices to address the protocol vulnerability.
http://technet.microsoft.com/en-us/security/advisory/2876146
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with