Short Name |
APP:KERBEROS:WIN-KERB-FALLBACK |
---|---|
Severity |
Major |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
APP |
Keywords |
Microsoft Windows Authentication Kerberos NTLM Fallback Security Bypass |
Release Date |
2016/09/07 |
Update Number |
2776 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
A security feature bypass vulnerability has been reported in the Kerberos authentication module of Microsoft Windows. Successful exploitation allows an attacker to alter the cached credentials on the target machine, providing access to the vulnerable machine as the target user.
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows man-in-the-middle attackers to bypass authentication via vectors related to a fallback to NTLM authentication during a domain account password change, aka "Kerberos Security Feature Bypass Vulnerability."