Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability - CVE-2024-20662ID: oval:org.secpod.oval:def:96650 | Date: (C)2024-01-10 (M)2024-04-17 |
Class: VULNERABILITY | Family: windows |
Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability. To successfully exploit this vulnerability the attacker must be an authenticated user that is granted the "manage online responder" permission. This permission defines who can use the Online Responder snap-in to modify the configuration of the Online Responder, and should be granted very selectively. The type of information that could be disclosed if an attacker successfully exploited this vulnerability is remote heap memory.
Platform: |
Microsoft Windows Server 2008 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows Server 2012 |
Microsoft Windows Server 2012 R2 |
Microsoft Windows Server 2016 |
Microsoft Windows Server 2019 |
Microsoft Windows Server 2022 |
Microsoft Windows Server |