Windows Cryptographic Services Remote Code Execution Vulnerability
Use after free in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.
Windows Cryptographic Services Remote Code Execution Vulnerability
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.
FAQ
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to send a large number of messages.
FAQ
How could an attacker exploit the vulnerability? An attacker can exploit this vulnerability by sending malicious fragmented ClientHello messages to a target server that accepts Transport Layer Security (TLS) connections.