Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-08-12 17:41
Updated : 2018-10-30 09:25
NVD link : CVE-2008-2246
Mitre link : CVE-2008-2246
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
microsoft
- windows_vista
- windows-nt