Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mgrj-fw6g-5692

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this vulnerability by changing how these requests are validated., aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0936.

An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this vulnerability by changing how these requests are validated., aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0936.

EPSS

Процентиль: 92%
0.08656
Низкий

Связанные уязвимости

CVSS3: 8.1
nvd
около 6 лет назад

An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this vulnerability by changing how these requests are validated., aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0936.

CVSS3: 7.8
msrc
около 6 лет назад

Windows Elevation of Privilege Vulnerability

CVSS3: 7.8
fstec
около 6 лет назад

Уязвимость реализации протокола Kerberos операционных систем Windows, связнная с ошибками в механизме аутентификации, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 92%
0.08656
Низкий