CVE Database
/

CVE-2016-0128

Back to search

CVE-2016-0128

Published: Apr 12, 2016

Modified: Aug 5, 2024

PUBLISHED

Description

The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 do not properly establish an RPC channel, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka "Windows SAM and LSAD Downgrade Vulnerability" or "BADLOCK."

VendorProductVersions

n/a

n/a

affected
n/a

References

http://badlock.org/
x_refsource_MISC
MS16-047
vendor-advisory
x_refsource_MS
VU#813296
third-party-advisory
x_refsource_CERT-VN
1035534
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now