Secunia Logo
 
Microsoft Windows IPsec Policy Processing Information Disclosure
Secunia Advisory: SA31411
Release Date: 2008-08-12
Popularity: 1,980 views

Critical:
Less critical
Impact: Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch

OS:Microsoft Windows Server 2008
Microsoft Windows Vista

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2008-2246


Description:
A security issue has been reported in Microsoft Windows, which may expose sensitive information to malicious people

The problem is caused due to an error in the manner IPsec policies are imported to Windows Server 2008 domains from Windows Server 2003 domains. This may result in systems ignoring IPsec policies and thus transmit data otherwise intended to be encrypted in clear text.

Solution:
Apply patches.

Windows Vista (optionally with SP1):
http://www.microsoft.com/downloads/de...=3f21a8a2-9861-4fef-9d1e-caf5f7822c1a

Windows Vista x64 Edition (optionally with SP1):
http://www.microsoft.com/downloads/de...=aa04a754-fbfb-42a7-89d2-14373e3f4742

Windows Server 2008 for 32-bit Systems:
http://www.microsoft.com/downloads/de...=c3363df6-39dc-4910-9ce5-66553155378e

Windows Server 2008 for x64-based Systems:
http://www.microsoft.com/downloads/de...=39dd1722-412b-469d-a475-b6513764838c

Windows Server 2008 for Itanium-based Systems:
http://www.microsoft.com/downloads/de...=e9c6cd46-30ad-46ee-9c8b-d0b446e660c4

Provided and/or discovered by:
Reported by the vendor.

Original Advisory:
MS08-047 (KB953733):
http://www.microsoft.com/technet/security/Bulletin/MS08-047.mspx


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 65 views
2. VLC Media Player Real Demuxer Integer Overflow Vulnerability // 64 views
3. Microsoft Office Communications Server SIP INVITE Denial of Service // 31 views
4. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 28 views
5. CAPICOM CAPICOM.Certificates ActiveX Control Vulnerability // 27 views
6. Basic PHP CMS "id" SQL Injection Vulnerability // 23 views
7. Active Photo Gallery "username" and "password" SQL Injection // 23 views
8. Active Newsletter "email" and "password" SQL Injection Vulnerabilities // 21 views
9. phpBB Cross Site Scripting and Unspecified Vulnerabilities // 19 views
10. Active eWebquiz "useremail" and "password" SQL Injection Vulnerabilities // 19 views