CVE-2016-0049

Description

Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which allows remote attackers to bypass authentication by deploying a crafted Key Distribution Center (KDC) and then performing a sign-in action, aka Windows Kerberos Security Feature Bypass.

Risk Information

Base Score
6.2
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
3.532

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows 10 for x64-based Systems (KB3135174)Windows
Cumulative Update for Windows 10 Version 1511 (KB3135173)Windows
Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3135173)Windows
Security Update for Windows Vista (KB3126587)Windows
Security Update for Windows Server 2008 (KB3126587)Windows
Security Update for Windows 7 (KB3126587)Windows
Security Update for Windows 8.1 (KB3126587)Windows
Security Update for Windows Vista for x64-based Systems (KB3126587)Windows
Security Update for Windows Server 2008 x64 Edition (KB3126587)Windows
Security Update for Windows 7 for x64-based Systems (KB3126587)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB3126587)Windows
Security Update for Windows Server 2012 (KB3126587)Windows
Security Update for Windows 8.1 for x64-based Systems (KB3126587)Windows
Security Update for Windows Server 2012 R2 (KB3126587)Windows
Security Update for Windows Vista (KB3126593)Windows
Security Update for Windows Server 2008 (KB3126593)Windows
Security Update for Windows 7 (KB3126593)Windows
Security Update for Windows 8.1 (KB3126593)Windows
Security Update for Windows Vista for x64-based Systems (KB3126593)Windows
Security Update for Windows Server 2008 x64 Edition (KB3126593)Windows
Security Update for Windows 7 for x64-based Systems (KB3126593)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB3126593)Windows
Security Update for Windows Server 2012 (KB3126593)Windows
Security Update for Windows 8.1 for x64-based Systems (KB3126593)Windows
Security Update for Windows Server 2012 R2 (KB3126593)Windows
Security Update for Windows 8.1 (KB3126434)Windows
Security Update for Windows 8.1 for x64-based Systems (KB3126434)Windows
Security Update for Windows Server 2012 R2 (KB3126434)Windows
Security Update for Windows Vista (KB3126041)Windows
Security Update for Windows Server 2008 (KB3126041)Windows
Security Update for Windows 8.1 (KB3126041)Windows
Security Update for Windows Vista for x64-based Systems (KB3126041)Windows
Security Update for Windows Server 2008 x64 Edition (KB3126041)Windows
Security Update for Windows 8.1 for x64-based Systems (KB3126041)Windows
Security Update for Windows Server 2012 R2 (KB3126041)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-19983Security Update for Windows 10 for x64-based Systems (KB3135174)
PATCH-19984Cumulative Update for Windows 10 Version 1511 (KB3135173)
PATCH-19985Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3135173)
PATCH-20021Security Update for Windows Vista (KB3126587)
PATCH-20022Security Update for Windows Server 2008 (KB3126587)
PATCH-20023Security Update for Windows 7 (KB3126587)
PATCH-20024Security Update for Windows 8.1 (KB3126587)
PATCH-20025Security Update for Windows Vista for x64-based Systems (KB3126587)
PATCH-20026Security Update for Windows Server 2008 x64 Edition (KB3126587)
PATCH-20027Security Update for Windows 7 for x64-based Systems (KB3126587)
PATCH-20028Security Update for Windows Server 2008 R2 x64 Edition (KB3126587)
PATCH-20029Security Update for Windows Server 2012 (KB3126587)
PATCH-20030Security Update for Windows 8.1 for x64-based Systems (KB3126587)
PATCH-20031Security Update for Windows Server 2012 R2 (KB3126587)
PATCH-20032Security Update for Windows Vista (KB3126593)
PATCH-20033Security Update for Windows Server 2008 (KB3126593)
PATCH-20034Security Update for Windows 7 (KB3126593)
PATCH-20035Security Update for Windows 8.1 (KB3126593)
PATCH-20036Security Update for Windows Vista for x64-based Systems (KB3126593)
PATCH-20037Security Update for Windows Server 2008 x64 Edition (KB3126593)
PATCH-20038Security Update for Windows 7 for x64-based Systems (KB3126593)
PATCH-20039Security Update for Windows Server 2008 R2 x64 Edition (KB3126593)
PATCH-20040Security Update for Windows Server 2012 (KB3126593)
PATCH-20041Security Update for Windows 8.1 for x64-based Systems (KB3126593)
PATCH-20042Security Update for Windows Server 2012 R2 (KB3126593)
PATCH-20043Security Update for Windows 8.1 (KB3126434)
PATCH-20044Security Update for Windows 8.1 for x64-based Systems (KB3126434)
PATCH-20045Security Update for Windows Server 2012 R2 (KB3126434)
PATCH-20046Security Update for Windows Vista (KB3126041)
PATCH-20047Security Update for Windows Server 2008 (KB3126041)
PATCH-20048Security Update for Windows 8.1 (KB3126041)
PATCH-20049Security Update for Windows Vista for x64-based Systems (KB3126041)
PATCH-20050Security Update for Windows Server 2008 x64 Edition (KB3126041)
PATCH-20131Security Update for Windows 8.1 for x64-based Systems (KB3126041)
PATCH-20132Security Update for Windows Server 2012 R2 (KB3126041)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234