Check: 2013-B-0003
windows 7 iavm:
2013-B-0003
(in version v1 r32)
Title
Microsoft Windows Security Bypass Vulnerability (Cat I impact)
Discussion
Microsoft has released a security bulletin addressing a vulnerability in the SSL and TLS implementation in Microsoft Windows. To exploit this vulnerability, an attacker would inject malformed traffic into an SSL version 3 or TLS browsing session between Internet Explorer and a third-party server or a third-party client and a Microsoft server. If successfully exploited, this vulnerability would allow an attacker to downgrade a SSL version 3 or TLS connection to SSL version 2 potentially compromising the confidentiality and integrity of the data in transit.
Check Content
Fix Text
Additional Identifiers
Rule ID:
Vulnerability ID: V-36450
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |