First published: Tue Sep 18 2012(Updated: )
Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid certificate.
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Phone | =7 | |
All of | ||
Microsoft Windows Phone 7 Firmware | ||
Microsoft Windows Phone 7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2993 is considered a medium-severity vulnerability due to its potential for man-in-the-middle attacks.
To mitigate CVE-2012-2993, it is recommended to update to a more secure version of Windows Phone or disable the use of non-verified certificates.
CVE-2012-2993 can facilitate man-in-the-middle attacks on POP3, IMAP, or SMTP protocols.
CVE-2012-2993 affects Microsoft Windows Phone version 7 and its firmware.
Exploiting CVE-2012-2993 may allow attackers to intercept and modify communications, leading to data breaches or loss of confidentiality.