Логотип exploitDog
bind:CVE-2019-1040
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-1040

Количество 4

Количество 4

nvd логотип

CVE-2019-1040

около 6 лет назад

A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. To exploit this vulnerability, the attacker would need to tamper with the NTLM exchange. The attacker could then modify flags of the NTLM packet without invalidating the signature. The update addresses the vulnerability by hardening NTLM MIC protection on the server-side.

CVSS3: 5.3
EPSS: Высокий
msrc логотип

CVE-2019-1040

около 6 лет назад

Windows NTLM Tampering Vulnerability

CVSS3: 5.3
EPSS: Высокий
github логотип

GHSA-8vpr-83m7-3f7q

около 3 лет назад

A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.

CVSS3: 5.3
EPSS: Высокий
fstec логотип

BDU:2019-02252

около 6 лет назад

Уязвимость операционной системы Windows, связанная с некорректной работой механизма защиты NTLM MIC (Message Integrity Check), позволяющая нарушителю понизить функции безопасности механизма NTLM

CVSS3: 5.9
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-1040

A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. To exploit this vulnerability, the attacker would need to tamper with the NTLM exchange. The attacker could then modify flags of the NTLM packet without invalidating the signature. The update addresses the vulnerability by hardening NTLM MIC protection on the server-side.

CVSS3: 5.3
88%
Высокий
около 6 лет назад
msrc логотип
CVE-2019-1040

Windows NTLM Tampering Vulnerability

CVSS3: 5.3
88%
Высокий
около 6 лет назад
github логотип
GHSA-8vpr-83m7-3f7q

A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.

CVSS3: 5.3
88%
Высокий
около 3 лет назад
fstec логотип
BDU:2019-02252

Уязвимость операционной системы Windows, связанная с некорректной работой механизма защиты NTLM MIC (Message Integrity Check), позволяющая нарушителю понизить функции безопасности механизма NTLM

CVSS3: 5.9
88%
Высокий
около 6 лет назад

Уязвимостей на страницу