Lucene search

K
cve[email protected]CVE-2009-0089
HistoryApr 15, 2009 - 8:00 a.m.

CVE-2009-0089

2009-04-1508:00:00
CWE-20
web.nvd.nist.gov
46
windows http services
winhttp
microsoft
cve-2009-0089
dns spoofing
https
vulnerability
nvd

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.3%

Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to β€œforward a connection” to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka β€œWindows HTTP Services Certificate Name Mismatch Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_2000sp4
OR
microsoftwindows_server_2003
OR
microsoftwindows_server_2003sp1
OR
microsoftwindows_server_2003sp1itanium
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_server_2008itanium
OR
microsoftwindows_server_2008x32
OR
microsoftwindows_server_2008x64
OR
microsoftwindows_vistax64
OR
microsoftwindows_vistagold
OR
microsoftwindows_vistasp1
OR
microsoftwindows_xppro_x64
OR
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp2pro_x64
OR
microsoftwindows_xpsp3

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.3%