#VU68136 Spoofing attack in Windows Server and Windows - CVE-2022-34689
Published: October 11, 2022 / Updated: January 27, 2023
Windows Server
Windows
Microsoft
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data in the Windows CryptoAPI. A remote attacker can manipulate an existing public x.509 certificate, spoof page content and and perform actions such as authentication or code signing as the targeted certificate.