Microsoft Windows IPsec Information Disclosure Vulnerability
BID:30634
Info
Microsoft Windows IPsec Information Disclosure Vulnerability
| Bugtraq ID: | 30634 |
| Class: | Unknown |
| CVE: |
CVE-2008-2246 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2008 12:00AM |
| Updated: | Aug 25 2008 04:45PM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Windows Vista x64 Edition SP1 Microsoft Windows Vista x64 Edition 0 Microsoft Windows Vista Ultimate SP1 Microsoft Windows Vista Ultimate Microsoft Windows Vista SP1 Microsoft Windows Vista Home Premium SP1 Microsoft Windows Vista Home Premium Microsoft Windows Vista Home Basic SP1 Microsoft Windows Vista Home Basic Microsoft Windows Vista Enterprise SP1 Microsoft Windows Vista Enterprise Microsoft Windows Vista Business SP1 Microsoft Windows Vista Business Microsoft Windows Vista 0 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems 0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows IPsec Information Disclosure Vulnerability
Microsoft Windows is prone to a vulnerability in the IPsec implementation.
The vulnerability causes IPsec policies that are imported from a Windows Server 2003 domain to a Windows Server 2008 domain to be ignored. This will cause network traffic to be transmitted in clear text instead of being encrypted.
Microsoft Windows is prone to a vulnerability in the IPsec implementation.
The vulnerability causes IPsec policies that are imported from a Windows Server 2003 domain to a Windows Server 2008 domain to be ignored. This will cause network traffic to be transmitted in clear text instead of being encrypted.
Exploit / POC
Microsoft Windows IPsec Information Disclosure Vulnerability
To exploit this issue, attackers can use a network sniffer.
To exploit this issue, attackers can use a network sniffer.
Solution / Fix
Microsoft Windows IPsec Information Disclosure Vulnerability
Solution:
Microsoft has released a security bulletin to address this vulnerability.
Microsoft Windows Vista SP1
Microsoft Windows Server 2008 for x64-based Systems 0
Microsoft Windows Vista Home Basic
Microsoft Windows Vista Business SP1
Microsoft Windows Vista Home Premium
Microsoft Windows Vista Enterprise
Microsoft Windows Vista Ultimate
Microsoft Windows Server 2008 for Itanium-based Systems 0
Microsoft Windows Server 2008 for 32-bit Systems 0
Microsoft Windows Vista x64 Edition 0
Microsoft Windows Vista Home Premium SP1
Microsoft Windows Vista Business
Microsoft Windows Vista 0
Microsoft Windows Vista x64 Edition SP1
Microsoft Windows Vista Ultimate SP1
Microsoft Windows Vista Home Basic SP1
Microsoft Windows Vista Enterprise SP1
Solution:
Microsoft has released a security bulletin to address this vulnerability.
Microsoft Windows Vista SP1
-
Microsoft Security Update for Windows Vista (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861 -4fef-9d1e-caf5f7822c1a
Microsoft Windows Server 2008 for x64-based Systems 0
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=39dd1722-412b -469d-a475-b6513764838c
Microsoft Windows Vista Home Basic
-
Microsoft Security Update for Windows Vista (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861 -4fef-9d1e-caf5f7822c1a
Microsoft Windows Vista Business SP1
-
Microsoft Security Update for Windows Vista (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861 -4fef-9d1e-caf5f7822c1a
Microsoft Windows Vista Home Premium
-
Microsoft Security Update for Windows Vista (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861 -4fef-9d1e-caf5f7822c1a
Microsoft Windows Vista Enterprise
-
Microsoft Security Update for Windows Vista (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861 -4fef-9d1e-caf5f7822c1a
Microsoft Windows Vista Ultimate
-
Microsoft Security Update for Windows Vista (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861 -4fef-9d1e-caf5f7822c1a
Microsoft Windows Server 2008 for Itanium-based Systems 0
-
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=e9c6cd46-30ad -46ee-9c8b-d0b446e660c4
Microsoft Windows Server 2008 for 32-bit Systems 0
-
Microsoft Security Update for Windows Server 2008 (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=c3363df6-39dc -4910-9ce5-66553155378e
Microsoft Windows Vista x64 Edition 0
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=aa04a754-fbfb -42a7-89d2-14373e3f4742
Microsoft Windows Vista Home Premium SP1
-
Microsoft Security Update for Windows Vista (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861 -4fef-9d1e-caf5f7822c1a
Microsoft Windows Vista Business
-
Microsoft Security Update for Windows Vista (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861 -4fef-9d1e-caf5f7822c1a
Microsoft Windows Vista 0
-
Microsoft Security Update for Windows Vista (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861 -4fef-9d1e-caf5f7822c1a
Microsoft Windows Vista x64 Edition SP1
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=aa04a754-fbfb -42a7-89d2-14373e3f4742
Microsoft Windows Vista Ultimate SP1
-
Microsoft Security Update for Windows Vista (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861 -4fef-9d1e-caf5f7822c1a
Microsoft Windows Vista Home Basic SP1
-
Microsoft Security Update for Windows Vista (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861 -4fef-9d1e-caf5f7822c1a
Microsoft Windows Vista Enterprise SP1
-
Microsoft Security Update for Windows Vista (KB953733)
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861 -4fef-9d1e-caf5f7822c1a
References
Microsoft Windows IPsec Information Disclosure Vulnerability
References:
References:
- Microsoft Security Bulletin MS08-047 (Microsoft)