SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a servers X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a triple handshake attack, aka TLS Server Certificate Renegotiation Vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Internet_explorer | Microsoft | 6 (including) | 6 (including) |
Internet_explorer | Microsoft | 7 (including) | 7 (including) |
Internet_explorer | Microsoft | 8 (including) | 8 (including) |
Internet_explorer | Microsoft | 9 (including) | 9 (including) |
Internet_explorer | Microsoft | 10 (including) | 10 (including) |
Internet_explorer | Microsoft | 11 (including) | 11 (including) |