CVE-2015-2434: Infoleak
Microsoft XML Core Services 3.0 and 5.0 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and conducting a decryption attack, aka "MSXML Information Disclosure Vulnerability," a different vulnerability than CVE-2015-2471.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2434?
CVE-2015-2434 has a critical severity rating due to its potential for information disclosure through decryption attacks.
How do I fix CVE-2015-2434?
To fix CVE-2015-2434, update Microsoft XML Core Services to version 6.0 or later, as this version does not support SSL 2.0.
What systems are affected by CVE-2015-2434?
CVE-2015-2434 affects Microsoft XML Core Services versions 3.0 and 5.0.
What are the risks associated with CVE-2015-2434?
The risks associated with CVE-2015-2434 include the potential for remote attackers to intercept and decrypt sensitive data transmitted over networks.
Is there a workaround for CVE-2015-2434?
A temporary workaround for CVE-2015-2434 is to disable SSL 2.0 on the affected systems until a patch can be applied.