Executive Summary
Summary | |
---|---|
Title | Microsoft Windows and Samba may allow spoofing of authenticated users ("Badlock") |
Informations | |||
---|---|---|---|
Name | VU#813296 | First vendor Publication | 2016-04-12 |
Vendor | VU-CERT | Last vendor Modification | 2016-04-14 |
Severity (Vendor) | N/A | Revision | M |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Vulnerability Note VU#813296Microsoft Windows and Samba may allow spoofing of authenticated users ("Badlock")OverviewThe Security Account Manager Remote (SAMR) and Local Security Authority (Domain Policy) (LSAD) protocols do not properly establish Remote Procedure Call (RPC) channels, which may allow any attacker to impersonate an authenticated user or gain access to the SAM database, or launch denial of service attacks. This vulnerability is also known publicly as "Badlock". Description
Impact
Solution
Vendor Information (Learn More)
CVSS Metrics (Learn More)
References
CreditCredit to Stefan Metzmacher for discovering and publicly disclosing this issue in coordination with Microsoft. This document was written by Garret Wassermann. Other Information
FeedbackIf you have feedback, comments, or additional information about this vulnerability, please send us email. |
Original Source
Url : http://www.kb.cert.org/vuls/id/813296 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-254 | Security Features |
CPE : Common Platform Enumeration
Snort® IPS/IDS
Date | Description |
---|---|
2016-05-12 | DCERPC Bind auth level packet privacy downgrade attempt RuleID : 38462 - Revision : 2 - Type : OS-WINDOWS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2017-05-01 | Name : The remote EulerOS host is missing multiple security updates. File : EulerOS_SA-2016-1014.nasl - Type : ACT_GATHER_INFO |
2016-12-27 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201612-47.nasl - Type : ACT_GATHER_INFO |
2016-05-26 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2950-5.nasl - Type : ACT_GATHER_INFO |
2016-05-19 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2950-4.nasl - Type : ACT_GATHER_INFO |
2016-05-12 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL37603172.nasl - Type : ACT_GATHER_INFO |
2016-05-05 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2950-3.nasl - Type : ACT_GATHER_INFO |
2016-05-02 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2950-2.nasl - Type : ACT_GATHER_INFO |
2016-04-22 | Name : The remote Fedora host is missing a security update. File : fedora_2016-383fce04e2.nasl - Type : ACT_GATHER_INFO |
2016-04-21 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-490.nasl - Type : ACT_GATHER_INFO |
2016-04-19 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2950-1.nasl - Type : ACT_GATHER_INFO |
2016-04-18 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2016-106-02.nasl - Type : ACT_GATHER_INFO |
2016-04-18 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-462.nasl - Type : ACT_GATHER_INFO |
2016-04-15 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-1028-1.nasl - Type : ACT_GATHER_INFO |
2016-04-15 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-1024-1.nasl - Type : ACT_GATHER_INFO |
2016-04-15 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-1023-1.nasl - Type : ACT_GATHER_INFO |
2016-04-15 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-1022-1.nasl - Type : ACT_GATHER_INFO |
2016-04-15 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0614.nasl - Type : ACT_GATHER_INFO |
2016-04-14 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-453.nasl - Type : ACT_GATHER_INFO |
2016-04-14 | Name : The remote Fedora host is missing a security update. File : fedora_2016-be53260726.nasl - Type : ACT_GATHER_INFO |
2016-04-14 | Name : The remote Fedora host is missing a security update. File : fedora_2016-48b3761baa.nasl - Type : ACT_GATHER_INFO |
2016-04-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3548.nasl - Type : ACT_GATHER_INFO |
2016-04-14 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2016-686.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20160412_samba_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20160412_samba_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0612.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2016-0611.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2016-0612.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2016-0613.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2016-0621.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_a636fc2600d911e6b704000c292e4fd8.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Windows host is affected by an elevation of privilege vulnerability. File : ms16-047.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2016-0611.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2016-0612.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2016-0613.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2016-0621.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0611.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0613.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0618.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0619.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0620.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0621.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0623.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0624.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Samba server is affected by multiple vulnerabilities. File : samba_4_3_7.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : An SMB server running on the remote host is affected by the Badlock vulnerabi... File : samba_badlock.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20160412_samba3x_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2016-04-13 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20160412_samba_and_samba4_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2016-04-12 | Name : The remote Windows host is affected by an elevation of privilege vulnerability. File : smb_nt_ms16-047.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2016-07-22 13:38:25 |
|
2016-07-07 21:27:02 |
|
2016-04-14 21:25:24 |
|
2016-04-13 21:29:42 |
|
2016-04-13 05:28:17 |
|
2016-04-12 21:23:31 |
|