Windows Certificate Enrollment Control Vulnerability Patch (Windows Me) 5.131.3659.0
Windows Certificate Enrollment Control Vulnerability Patch (Windows Me) 5.131.3659.0 Ranking & Summary
Windows Certificate Enrollment Control Vulnerability Patch (Windows Me) 5.131.3659.0 description
Windows Certificate Enrollment Control Vulnerability Patch (Windows Me) 5.131.3659.0 is developed as an all-in-one tool which is a combination of all versions of Windows ship with an ActiveX control, which can enable Web-based certificate enrollments.
The control contains a flaw that could enable a Web page, through an extremely complex process, to invoke the control in a way that would delete certificates on a user?s system. An attacker who successfully exploited the vulnerability could corrupt trusted root certificates, EFS encryption certificates, e-mail signing certificates, and any other certificates on the system, thereby preventing the user from using these features.
A new version of the control is available that corrects the vulnerability and can be installed via the patch. As discussed in the Caveats section, customers who operate Web sites that use the Certificate Enrollment Control will need to make minor revisions to their Web applications in order to use the new control.
Microsoft Knowledge Base article Q323172 details how to do this. In addition, the patch addresses a similar, but less serious vulnerability discovered in the SmartCard Enrollment control. This control ships with Windows 2000 and Windows XP. A new version of this control is also provided.
Windows Certificate Enrollment Control Vulnerability Patch (Windows Me) 5.131.3659.0 Screenshot
Windows Certificate Enrollment Control Vulnerability Patch (Windows Me) 5.131.3659.0 Keywords
Bookmark Windows Certificate Enrollment Control Vulnerability Patch (Windows Me) 5.131.3659.0
Windows Certificate Enrollment Control Vulnerability Patch (Windows Me) 5.131.3659.0 Copyright
Want to place your software product here?
Please contact us for consideration.
Contact WareSeeker.com
- EPSON Stylus Scan 2500 Smart Panel Patch 1.00A
- Windows ME Security Patches NA
- Microsoft Word 97 and 98 Patch: Malformed Conversi Update
- Microsoft Windows 98 Patch: Malformed RTF Control
- Microsoft Windows 95 Update: Malformed RTF Control
- Patch Me 2.10
- Microsoft Windows ME Patch: Levy Requests as User
- Microsoft Windows 98 Update: DHTML Edit Control
- Microsoft Word 2000 RTF Macro Vulnerability Patch
- Windows XP RPC Interface Buffer Overrun Security Vulnerability Patch 823980
- Microsoft Excel 2002 for Windows Macro Modification Security Vulnerability Patch MS01-050
- Windows Media Player 7 Skins File Download Vulnerability Patch 38041 (2/12/01)
- Microsoft Internet Explorer Active Setup Control Vulnerability patch 0
- Microsoft SQL Server Malformed TDS Packet Header Vulnerability patch 1
- Microsoft VM File Reading Vulnerability patch 1
- Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1
- Internet Explorer 5.01 Certificate Spoofing Vulnerability Patch MS01-027 (5/16/01)
- Microsoft Windows ME Security Patch: Share Level Password Vulnerability 10-10-00
- Microsoft Windows ME Security Patch: Web Client NTLM Authentication Vulnerability MS01-001
- Internet Explorer 5.5 Scriptlet Rendering Vulnerability Patch
- Visual FoxPro 6.0 Launch Security Vulnerability Patch MS02-049
- Microsoft Data Access Components 2.7 Unchecked Buffer Vulnerability Patch MS02-040
- Personal Web Server File Access Vulnerability Patch (FrontPage 98)
- Microsoft XML 3.0 Core Services Vulnerability Patch MS02-008