Nabeel Ahmed

Pesquisador deNTT Belgium
#2179de 53,638
109CVSS total
Vulnerabilidades · 16
Baixa
1
Média
7
Alta
7
Crítica
1
PT-2016-2591
9.3
2016-08-09
Microsoft · Windows Vista · CVE-2016-3237
**Name of the Vulnerable Software and Affected Versions** Microsoft Windows Vista SP2 Microsoft Windows Server 2008 SP2 and R2 SP1 Microsoft Windows 7 SP1 Microsoft Windows 8.1 Microsoft Windows Server 2012 Gold and R2 Microsoft Windows RT 8.1 Microsoft Windows 10 Gold, 1511, and 1607 **Description** The issue allows man-in-the-middle attackers to bypass authentication via vectors related to a fallback to NTLM authentication during a domain account password change. This is due to insufficient access restrictions in the Windows operating system, which can be exploited by a remote attacker to bypass the authentication procedure by affecting the NTLM authentication system during a domain account password change. **Recommendations** For Microsoft Windows Vista SP2, update to a newer version to mitigate the risk. For Microsoft Windows Server 2008 SP2 and R2 SP1, update to a newer version to mitigate the risk. For Microsoft Windows 7 SP1, update to a newer version to mitigate the risk. For Microsoft Windows 8.1, update to a newer version to mitigate the risk. For Microsoft Windows Server 2012 Gold and R2, update to a newer version to mitigate the risk. For Microsoft Windows RT 8.1, update to a newer version to mitigate the risk. For Microsoft Windows 10 Gold, 1511, and 1607, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the NTLM authentication system during domain account password changes until a patch is available.
PT-2016-1228
6.2
2016-02-09
Microsoft · Windows 7 · CVE-2016-0049
**Name of the Vulnerable Software and Affected Versions** Microsoft Windows Vista SP2 Microsoft Windows Server 2008 SP2 and R2 SP1 Microsoft Windows 7 SP1 Microsoft Windows 8.1 Microsoft Windows Server 2012 Gold and R2 Microsoft Windows 10 Gold and 1511 **Description** The issue is related to the Kerberos component in Microsoft Windows, which does not properly validate password changes. This allows remote attackers to bypass authentication by deploying a crafted Key Distribution Center (KDC) and then performing a sign-in action. The vulnerability is also related to errors in managing registration data, which can be exploited by a local attacker to bypass the authentication procedure. Additionally, the vulnerability can be used to bypass Kerberos authentication on a target machine and decrypt drives protected by BitLocker. **Recommendations** For Microsoft Windows Vista SP2, update the operating system to address the issue. For Microsoft Windows Server 2008 SP2 and R2 SP1, apply the necessary security patches to resolve the vulnerability. For Microsoft Windows 7 SP1, install the latest security updates to fix the issue. For Microsoft Windows 8.1, apply the recommended security fixes to mitigate the risk. For Microsoft Windows Server 2012 Gold and R2, update the system with the latest security patches. For Microsoft Windows 10 Gold and 1511, install the necessary security updates to address the vulnerability. As a temporary workaround, consider restricting access to the Kerberos authentication mechanism until a patch is available.