SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a servers X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a triple handshake attack, aka TLS Server Certificate Renegotiation Vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Internet_explorer | Microsoft | 6 | 6 |
Internet_explorer | Microsoft | 7 | 7 |
Internet_explorer | Microsoft | 8 | 8 |
Internet_explorer | Microsoft | 9 | 9 |
Internet_explorer | Microsoft | 10 | 10 |
Internet_explorer | Microsoft | 11 | 11 |