Microsoft XML Core Services 3.0, 5.0, and 6.0 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and conducting a decryption attack, aka “MSXML Information Disclosure Vulnerability,” a different vulnerability than CVE-2015-2434.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2471
Reference (s):
- MS:MS15-084
- URL: https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-084
- SECTRACK:1033241
- URL: http://www.securitytracker.com/id/1033241

