SB2016021009 - Authenticatoin bypass in Microsoft Windows
Published: February 10, 2016 Updated: April 7, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2016-0049)
The vulnerability allows a local user to bypass authentication process.
The vulnerability exists due to security feature bypass in Windows when Kerberos fails to check
the password change of a user signing into a workstation.
An attacker could bypass Kerberos authentication by connecting a
workstation to a malicious Kerberos Key Distribution Center (KDC) and gain access to sensitive data.
Remediation
Install update from vendor's website.