Microsoft Windows CryptoAPI X.509 Spoofing Vulnerabilities (974571)

Summary
This host is missing a critical security update according to Microsoft Bulletin MS09-056.
Impact
Successful exploitation will allow attacker to conduct spoofing attacks on the affected system. Impact Level: System
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link. http://www.microsoft.com/technet/security/bulletin/ms09-056.mspx
Insight
- The issue is due to the Windows CryptoAPI incorrectly parsing a null terminator as the end of any values identified by an Object Identifier (OID) when processing ASN.1 information from X.509 certificates. - An integer overflow error in the Windows CryptoAPI when parsing ASN.1 object identifiers from X.509 certificates, which could allow an attacker to generate a malicious certificate that would be parsed incorrectly by the Windows CryptoAPI.
Affected
Micorsoft Windows 7 Microsoft Windows 2K Service Pack 4 and prior. Microsoft Windows XP Service Pack 3 and prior. Microsoft Windows 2K3 Service Pack 2 and prior. Microsoft Windows Vista Service Pack 1/2 and prior. Microsoft Windows Server 2008 Service Pack 1/2 and prior.
References