🪟 Windows TippsModify Windows Support Phone Number with PowerShell(03.09.2026 um 00:00 Uhr)
🔧 AI Nachrichten Podcast: ChatGPT schwatzt Nutzern in Deutschland jetzt Werbung auf(28.08.2026 um 08:46 Uhr)
🪟 Windows TippsMicrosoft bringt Emoji 17.0 auf Windows 11(31.08.2026 um 08:16 Uhr)
🪟 Windows TippsModify Windows Support Phone Number with PowerShell(03.09.2026 um 00:00 Uhr)
🔧 AI Nachrichten Podcast: ChatGPT schwatzt Nutzern in Deutschland jetzt Werbung auf(28.08.2026 um 08:46 Uhr)
🪟 Windows TippsMicrosoft bringt Emoji 17.0 auf Windows 11(31.08.2026 um 08:16 Uhr)

🕵️ Sicherheitslücken 🕛 vor 3 Jahren 2 Min Lesezeit CVE-2022-42916
0

curl: CVE-2022-43551: Another HSTS bypass via IDN

Cyber Threat & Vulnerability Dossier CVSS 7.5 HIGH (Heuristik) EPSS 31.7%
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
Im CVE-Radar öffnen
↗ Quelle (vulners.com)
🔬 IoC Intelligence (2 Indikatoren erkannt)
CVE-2022-42916142[.]250[.]206[.]237
🗣️ Stimme:

image
Summary: I found an issue similar to CVE-2022-42916 again. Since the phenomenon is the same, I will describe the same as last time. HSTS checks are bypassed if any character in the IDN convert(Nameprep) to a '.' for example"。"(UTF-8:E38082). I think there are other characters that become ".(UTF-8:2E)" as a result of converting with IDN. This is because the host name before IDN conversion is used when writing to the HSTS cache. Steps To Reproduce: [add details for how we can reproduce the issue] Start from a state where there is no entry for the access destination host name in the HSTS cache curl -v --hsts hsts.txt https://accounts.google%E3%80%82com curl -v --hsts hsts.txt http://accounts.google%E3%80%82com Result of 3. ``` C:\test\curl-7.86.0-win64-mingw\bin>curl -v --hsts hsts.txt http://accounts.google%E3%80%82com --head * Trying 142.250.206.237:80... * Connected to accounts.google縲Dom (142.250.206.237) port 80 (#0) HEAD / HTTP/1.1 Host: accounts.google.com User-Agent: curl/7.86.0 Accept: / ``` If you execute 3. after executing the below, you will access the site with HTTPS. curl -v --hsts hsts.txt https://accounts.google.com I use this in a Windows environment. I checked the HSTS cache after executing 2. and found the host name before IDN conversion. ``` Your HSTS cache. https://curl.se/docs/hsts.html This file was generated by libcurl! Edit at your own risk. .accounts.google。com "20231029 15:57:29" ``` I think the problem is in http.c:line 3727....
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf vulners.com.
↗ Original-Artikel auf vulners.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Modify Windows Support Phone Number with PowerShell
1 Quelle
Die Zukunft des Einkaufens: Warum wir ein neues Kapitel aufschlagen (und wie du es mitschreiben kannst)
1 Quelle
ZDE Podcast 251: Wie sieht digitales Instore Marketing 2026 aus, Amit Chatterjee?
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten curl: CVE-2022-43551: Another HSTS bypass via IDN

Thematisch verwandte Begriffe: curl, CVE202243551, Another, HSTS · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...