PT-2016-2745 · Microsoft · Windows 8.1+2

Published

2016-09-13

·

Updated

2018-10-12

·

CVE-2016-3352

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions 8.1, 10 Gold, 1511, and 1607
Description The issue is related to incorrect checking of NTLM SSO requests for MSA logins, allowing remote attackers to determine passwords via a brute-force attack on NTLM password hashes. This can enable attackers to obtain sensitive information and affect the system.
Recommendations For Microsoft Windows versions 8.1, 10 Gold, 1511, and 1607, update to a version that properly checks NTLM SSO requests for MSA logins to prevent brute-force attacks on NTLM password hashes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-02147
CVE-2016-3352

Affected Products

Windows
Windows 10
Windows 8.1