CVE-2016-3352Improper Authorization in Microsoft Windows 10

Severity
8.8HIGHNVD
EPSS
32.9%
top 3.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 14
Latest updateMay 14

Description

Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it easier for remote attackers to determine passwords via a brute-force attack on NTLM password hashes, aka "Microsoft Information Disclosure Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

🔴Vulnerability Details

1
GHSA
GHSA-j53r-gx3g-g877: Microsoft Windows 82022-05-14

📋Vendor Advisories

1
Microsoft
Windows Information Disclosure Vulnerability2016-09-13

🕵️Threat Intelligence

2
Qualys
Large Microsoft Patch Tuesday Update for September 2016 | Qualys2016-09-13
Qualys
Large Microsoft Patch Tuesday Update for September 2016 | Qualys2016-09-13