This year is an unfortunate year For TLS. All major TLS stacks are found to have high-risk vulnerabilities.
Microsoft disclosed a high-risk vulnerability that affects all Windows versions. Windows users, especially website users, need to immediately install patches released by Microsoft on Tuesday. The vulnerability exists in Microsoft's TLS library, allowing attackers to send malicious traffic to Windows servers for remote code execution.
The disclosure of Microsoft's TLS vulnerability means that all major TLS stacks, including Apple's SecureTransport, GNUTLS, OpenSSL, NSS, and Microsoft Secure Channel (Schannel), have detected high-risk vulnerabilities this year.
Security researchers said machines may have vulnerabilities if users install and run monitoring port software that accepts encrypted connections. For example, Windows 7 users may face risks when installing an FTP server that accepts external connections.
This article permanently updates the link address: