PT-2015-2686 · Microsoft · Windows 8.1+10
Publicado
2015-11-10
·
Atualizado
2019-05-17
·
CVE-2015-6095
CVSS v2.0
4.9
Média
| Vetor | AV:L/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Windows Vista SP2
Windows Server 2008 SP2 and R2 SP1
Windows 7 SP1
Windows 8
Windows 8.1
Windows Server 2012 Gold and R2
Windows RT Gold and 8.1
Windows 10 Gold and 1511
Description
The issue is related to how Kerberos in Windows handles password changes, allowing physically proximate attackers to bypass authentication. This can lead to decryption attacks against certain BitLocker configurations by connecting to an unintended Key Distribution Center (KDC). The vulnerability is associated with errors in managing registration data, which can be exploited by a local attacker to bypass the authentication procedure or obtain BitLocker keys.
Recommendations
For Windows Vista SP2, update the system to address the Kerberos security feature bypass issue.
For Windows Server 2008 SP2 and R2 SP1, apply the necessary patch to fix the Kerberos authentication bypass vulnerability.
For Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511, ensure that Kerberos is properly configured to check password changes for users signing into a workstation, and consider restricting access to Key Distribution Centers (KDCs) to minimize the risk of exploitation.
As a temporary workaround, consider disabling Kerberos authentication on target machines until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bitlocker
Kerberos
Windows
Windows 10
Windows 7
Windows 8
Windows 8.1
Windows Rt
Windows Server 2008
Windows Server 2012
Windows Vista