CVE-2014-5854: Medium severity microsoft windows live hotmail vulnerability
The Windows Live Hotmail PUSH mail (aka com.clearhub.wl) application 1.00.97 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5854?
CVE-2014-5854 is rated as a high severity vulnerability due to its potential for enabling man-in-the-middle attacks.
How do I fix CVE-2014-5854?
To fix CVE-2014-5854, update the Windows Live Hotmail PUSH mail application to a version that properly verifies X.509 certificates.
What type of attack does CVE-2014-5854 allow?
CVE-2014-5854 allows attackers to execute man-in-the-middle attacks, enabling them to spoof servers and intercept sensitive information.
Which application is affected by CVE-2014-5854?
CVE-2014-5854 affects the Windows Live Hotmail PUSH mail application version 1.00.97 for Android.
Why is X.509 certificate verification important in relation to CVE-2014-5854?
X.509 certificate verification is crucial to ensure the authenticity of SSL servers, preventing attackers from impersonating them.