The verifycertificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly have unspecified other impact via a wildcard certificate name, which triggers an out-of-bounds read.
The verifycertificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted wildcard SAN in a server certificate, as demonstrated by ".com."
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation of Privilege Vulnerability".
End of life: 7/11/2023, End of support: 7/10/2018
End of life: 7/11/2023, End of support: 7/10/2018
End of life: 7/11/2023, End of support: 7/10/2018
End of life: 1/10/2023, End of support: 1/9/2018
End of life: 10/10/2023, End of support: 10/9/2018
End of life: 10/10/2023, End of support: 10/9/2018
End of life: 10/10/2023, End of support: 10/9/2018
End of life: 10/12/2021, End of support: 10/11/2016
End of life: 4/13/2021, End of support: 4/12/2016
End of life: 4/13/2021, End of support: 4/12/2016
End of life: 4/13/2021, End of support: 4/12/2016
End of life: 10/13/2020, End of support: 10/13/2015
Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitrary code via crafted (1) JPEG and (2) GIF images.