SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2001-0338

Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation…

MEDIUM 5.1EPSS 5.32%

Does this matter?

Lower severity and a low EPSS score (5.32%). Track it; it rarely justifies an emergency change on its own.

Description

Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability."

CVSS 2.0
5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS
5.32% probability · 92th percentile
CISA KEV
Not listed
Affected
microsoft/internet explorer
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.