60
CVE-2016-3237
PoC —CVSS 3.0
7.5 high
EPSS
17%p97
Published
()
Modified
Description
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows man-in-the-middle attackers to bypass authentication via vectors related to a fallback to NTLM authentication during a domain account password change, aka "Kerberos Security Feature Bypass Vulnerability."
- Vendors
- microsoft
- Products
- windows 10, windows 7, windows 8.1, windows rt, windows rt 8.1, windows server 2008, windows server 2012, windows vista
- Weakness
- CWE-264
- Vector
- CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H