PT-2016-2745 · Microsoft · Windows 8.1+2

Publicado

2016-09-13

·

Atualizado

2018-10-12

·

CVE-2016-3352

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions 8.1, 10 Gold, 1511, and 1607
Description The issue is related to incorrect checking of NTLM SSO requests for MSA logins, allowing remote attackers to determine passwords via a brute-force attack on NTLM password hashes. This can enable attackers to obtain sensitive information and affect the system.
Recommendations For Microsoft Windows versions 8.1, 10 Gold, 1511, and 1607, update to a version that properly checks NTLM SSO requests for MSA logins to prevent brute-force attacks on NTLM password hashes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-02147
CVE-2016-3352

Produtos afetados

Windows
Windows 10
Windows 8.1