CVE-2015-2471: Medium severity microsoft xml core services vulnerability
Microsoft XML Core Services 3.0, 5.0, and 6.0 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and conducting a decryption attack, aka "MSXML Information Disclosure Vulnerability," a different vulnerability than CVE-2015-2434.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2471?
CVE-2015-2471 is considered critical due to its potential for remote exploitation.
How do I fix CVE-2015-2471?
To fix CVE-2015-2471, upgrade to a version of Microsoft XML Core Services that does not support SSL 2.0.
Who is affected by CVE-2015-2471?
CVE-2015-2471 affects users of Microsoft XML Core Services versions 3.0, 5.0, and 6.0.
What kind of attack does CVE-2015-2471 enable?
CVE-2015-2471 enables remote attackers to conduct a decryption attack by sniffing the network.
Is CVE-2015-2471 a network vulnerability?
Yes, CVE-2015-2471 is a network vulnerability that allows attackers to exploit cryptographic weaknesses.