CVE-2014-1771
Microsoft Internet Explorer 6-11 - Info Disclosure
Title source: llmDescription
SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "TLS Server Certificate Renegotiation Vulnerability."
Exploits (1)
References (4)
Scores
EPSS
0.1342
EPSS Percentile
94.1%
Classification
CWE
CWE-310
Status
draft
Affected Products (6)
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
Timeline
Published
Jun 11, 2014
Tracked Since
Feb 18, 2026