CVE-2017-8495
published 2017-07-11CVE-2017-8495: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703…
PriorityP344high7.5CVSS 3.0
AVNACHPRLUINSUCHIHAH
EPSS
4.62%
90.7th percentile
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to bypass Extended Protection for Authentication when Kerberos fails to prevent tampering with the SNAME field during ticket exchange, aka "Kerberos SNAME Security Feature Bypass Vulnerability" or Orpheus' Lyre.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1511 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1703 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Kerberos SNAME Security Feature Bypass Vulnerability
vendor_msrc·2017-07-11·CVSS 7.5
CVE-2017-8495 [HIGH] Kerberos SNAME Security Feature Bypass Vulnerability
Kerberos SNAME Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists in Microsoft Windows when Kerberos fails to prevent tampering with the SNAME field during ticket exchange. An attacker who successfully exploited this vulnerability could use it to bypass Extended Protection for Authentication.
To exploit this vulnerability, an attacker would have to be able to launch a man-in-the-middle (MiTM) attack against the traffic passing between a client and the server.
The update addresses this vulnerability by adding integrity protection to the SNAME field.
Kerberos: Kerberos
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4025342
Reference:
GHSA
GHSA-95f7-rc94-rqj7: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8
ghsa_unreviewed·2022-05-17
CVE-2017-8495 [HIGH] CWE-287 GHSA-95f7-rc94-rqj7: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to bypass Extended Protection for Authentication when Kerberos fails to prevent tampering with the SNAME field during ticket exchange, aka "Kerberos SNAME Security Feature Bypass Vulnerability" or Orpheus' Lyre.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-10388 OpenJDK: use of unprotected sname in Kerberos client (Libraries, 8178794)
bugzilla·2017-10-13·CVSS 7.5
CVE-2017-10388 [HIGH] CVE-2017-10388 OpenJDK: use of unprotected sname in Kerberos client (Libraries, 8178794)
CVE-2017-10388 OpenJDK: use of unprotected sname in Kerberos client (Libraries, 8178794)
It was discovered that the Kerberos client implementation in the Libraries component of OpenJDK used the sname field from the plain text part rather than encrypted part of the KDC reply. A man-in-the-middle attacker could possibly use this flaw to impersonate Kerberos services to Java applications acting as Kerberos clients.
Discussion:
Apparently another Kerberos implementation affected by the "Orpheus' Lyre" vulnerability:
https://www.orpheus-lyre.info/
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8495
---
Public now via Oracle CPU October 2017:
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html#AppendixJAVA
The issue was fixed in Oracle
Talos
Microsoft Patch Tuesday - July 2017
blogs_talos·2017-07-11·CVSS 7.8
CVE-2017-8463 [HIGH] Microsoft Patch Tuesday - July 2017
Today, Microsoft has release their monthly set of security updates designed to address vulnerabilities. This month's release addresses 54 vulnerabilities with 19 of them rated critical, 32 rated important, and 3 rated moderate. Impacted products include Edge, .NET Framework, Internet Explorer, Office, and Windows.
### Vulnerabilities Rated Critical
#### CVE-2017-8463
This is a remote code execution vulnerability related to the way that Windows Explorer handles executable files and shares during rename operations. If exploited this vulnerability could run arbitrary code, users not running as administrators would be less affected. This vulnerability can be triggered via a malicious share folder and malware named with an executable extension.
#### CVE-2017-8584 A remote code execution vul
http://www.securityfocus.com/bid/99424http://www.securitytracker.com/id/1038862https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8495https://www.orpheus-lyre.info/http://www.securityfocus.com/bid/99424http://www.securitytracker.com/id/1038862https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8495https://www.orpheus-lyre.info/
2017-07-11
Published