Microsoft Windows Phone 7 contains a flaw that is triggered when the device fails to properly validate the domain name in the subject's Common Name (CN) field of an X.509 certificate. This may allow a remote man-in-the-middle attacker to spoof an SSL server with an arbitrary valid certificate for the POP3, IMAP, or SMTP protocols.
Classification
Location:
Remote / Network Access,
Mobile Phone / Hand-held Device
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Uncoordinated Disclosure
Solution
OSVDB is not aware of a solution for this vulnerability, though Microsoft has acknowledged the issue and stated they will release a fix.