HIGH
DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify server X.509 certificates, which allows man-in-the-middle attackers to spoof servers and read encrypted domain credentials via a crafted certificate
Published Nov 16, 2013
7.1
HIGHCVSS 2.0
EPSS 4.76%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.