CVE Database
/

CVE-2016-3237

Back to search

CVE-2016-3237

Published: Aug 9, 2016

Modified: Aug 5, 2024

PUBLISHED

Description

Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows man-in-the-middle attackers to bypass authentication via vectors related to a fallback to NTLM authentication during a domain account password change, aka "Kerberos Security Feature Bypass Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

92290
vdb-entry
x_refsource_BID
MS16-101
vendor-advisory
x_refsource_MS
1036576
vdb-entry
x_refsource_SECTRACK
40409
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now