Skip to main content
MSRC

Security Advisory 2743314 released

Today, we published Security Advisory 2743314, which provides guidance that will help protect customers from a technique that could allow a man-in-the middle attack to obtain a user’s domain credentials when VPN is configured to use PPTP and MSCHAPv2.

Customers concerned with this scenario are advised to review the guidance described in the advisory to help protect themselves. We encourage customers to review our guidance and evaluate the risk and cost to their individual environments.

For all the latest information, you can also follow the MSRC team on Twitter at @MSFTSecResponse.

Thanks,
Yunsun Wee
Director, Microsoft Trustworthy Computing


How satisfied are you with the MSRC Blog?

Rating

Feedback * (required)

Your detailed feedback helps us improve your experience. Please enter between 10 and 2,000 characters.

Thank you for your feedback!

We'll review your input and work on improving the site.