Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability - CVE-2024-20655ID: oval:org.secpod.oval:def:96646 | Date: (C)2024-01-10 (M)2024-04-17 |
Class: VULNERABILITY | Family: windows |
Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability. Successful exploitation of this vulnerability requires an attacker to win a race condition. To successfully exploit this vulnerability the attacker must be an authenticated user that is granted the "manage online responder" permission. This permission defines who can use the Online Responder snap-in to modify the configuration of the Online Responder, and should be granted very selectively.
Platform: |
Microsoft Windows Server 2008 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows Server 2012 |
Microsoft Windows Server 2012 R2 |
Microsoft Windows Server 2016 |
Microsoft Windows Server 2019 |
Microsoft Windows Server 2022 |
Microsoft Windows Server |