Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6060 | signature vdb entry |
http://www.us-cert.gov/cas/techalerts/TA08-225A.html | third party advisory us government resource |
http://marc.info/?l=bugtraq&m=121915960406986&w=2 | vendor advisory |
http://secunia.com/advisories/31411 | patch vendor advisory third party advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-047 | vendor advisory |
http://www.vupen.com/english/advisories/2008/2351 | vdb entry |
http://www.securitytracker.com/id?1020678 | vdb entry |
http://www.securityfocus.com/bid/30634 | patch vdb entry |