Improperly Issued and Inadvertently Disclosed Digital Certificates Could Allow Spoofing
greetings,
i see 3 vulnerabilities on scan. 2 patches(kb2813430,kb3097966) installed on server out of three(kb2677070,kb2813430,kb3097966) vulns. installing kb2677070 fix 3 vulns? i trying check needed automatic updater? use windows update? ports required? if have disconnected environment (no internet connection). below details on vulnerabilities.
ms kb3119884: improperly issued digital certificates allow spoofing
plugin text:
plugin output:
the remote host has kb2677070 or kb2813430, disallowed ctl has not been updated.
synopsis:
the remote windows host has out-of-date ssl certificate blacklist.
description:the remote host missing kb3119884, kb2677070 (automatic updater), or latest disallowed certificate update using kb2813430
(manual updater). if kb2677070 has been installed, has not yet obtained latest auto-updates.
note plugin checks updaters have updated disallowed ctl list, not kbs listed installed. approach was
taken since kb2677070 automatic updater isn't triggered unless software relies on ssl in microsoft cryptography api being actively
used on remote host.
solution:ensure microsoft automatic updater revoked certificates (kb2677070) installed , running. alternatively, install manual
updater (kb2813430).
see also:https://technet.microsoft.com/en-us/library/security/3119884
http://support.microsoft.com/en-us/kb/3046310
http://support.microsoft.com/en-us/kb/2677070
http://support.microsoft.com/en-us/kb/2813430
ms kb3123040: improperly issued digital certificates allow spoofing
plugin text:
plugin output:
the remote host has kb2677070 or kb2813430, disallowed ctl has not been updated.
synopsis:the remote windows host has out-of-date ssl certificate blacklist.
description:the remote host missing kb3046310, kb2677070 (automatic updater), or latest disallowed certificate update using kb2813430
(manual updater). if kb2677070 has been installed, has not yet obtained latest auto-updates.
note plugin checks updaters have updated disallowed ctl list, not kbs listed installed. approach was
taken since kb2677070 automatic updater isn't triggered unless software relies on ssl in microsoft cryptography api being actively
used on remote host.
solution:ensure microsoft automatic updater revoked certificates (kb2677070) installed , running.
see also:https://technet.microsoft.com/en-us/library/security/3123040
http://support.microsoft.com/en-us/kb/3046310
http://support.microsoft.com/en-us/kb/2677070
http://support.microsoft.com/en-us/kb/2813430
ms kb3097966: inadvertently disclosed digital certificates allow spoofing
plugin text:
plugin output:
the remote host has kb2677070 or kb2813430, disallowed ctl has not been updated.
synopsis:the remote windows host has out-of-date ssl certificate blacklist.
description:the remote host missing kb3097966, kb2677070 (automatic updater), or latest disallowed certificate update using kb2813430
(manual updater). if kb2677070 has been installed, has not yet obtained latest auto-updates.
note plugin checks updaters have updated disallowed ctl list, not kbs listed installed. approach was
taken since kb2677070 automatic updater isn't triggered unless software relies on ssl in microsoft cryptography api being actively
used on remote host.
solution:ensure kb3097966 security update has been installed , microsoft automatic updater revoked certificates installed
and running.
see also:
https://technet.microsoft.com/en-us/library/security/3097966
https://support.microsoft.com/en-us/kb/2677070
https://support.microsoft.com/en-us/kb/2813430
https://support.microsoft.com/en-us/kb/3097966
i appreciate can get.
samikhanwwk
thank taking time out , give me idea resolve issue. helped.
i have done more research , found 100% resolve. below link it.
https://technet.microsoft.com/en-us/library/dn265983.aspx
regards,
samikhanwwk
Windows Server > WSUS
Comments
Post a Comment