PT-2016-2745 · Microsoft · Windows 8.1+2
Published
2016-09-13
·
Updated
2018-10-12
·
CVE-2016-3352
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions 8.1, 10 Gold, 1511, and 1607
Description
The issue is related to incorrect checking of NTLM SSO requests for MSA logins, allowing remote attackers to determine passwords via a brute-force attack on NTLM password hashes. This can enable attackers to obtain sensitive information and affect the system.
Recommendations
For Microsoft Windows versions 8.1, 10 Gold, 1511, and 1607, update to a version that properly checks NTLM SSO requests for MSA logins to prevent brute-force attacks on NTLM password hashes.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 10
Windows 8.1