Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8vpr-83m7-3f7q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.

A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.

EPSS

Процентиль: 99%
0.86668
Высокий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 6 лет назад

A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. To exploit this vulnerability, the attacker would need to tamper with the NTLM exchange. The attacker could then modify flags of the NTLM packet without invalidating the signature. The update addresses the vulnerability by hardening NTLM MIC protection on the server-side.

CVSS3: 5.3
msrc
около 6 лет назад

Windows NTLM Tampering Vulnerability

CVSS3: 5.9
fstec
около 6 лет назад

Уязвимость операционной системы Windows, связанная с некорректной работой механизма защиты NTLM MIC (Message Integrity Check), позволяющая нарушителю понизить функции безопасности механизма NTLM

EPSS

Процентиль: 99%
0.86668
Высокий

5.3 Medium

CVSS3