Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfr7-2ph8-36r9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a Domain Controller.

Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a Domain Controller.

EPSS

Процентиль: 91%
0.06304
Низкий

Дефекты

CWE-294

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a Domain Controller.

EPSS

Процентиль: 91%
0.06304
Низкий

Дефекты

CWE-294