Man-in-the-Middle (MitM) attack in Microsoft Windows and Windows Server - CVE-2019-1166
Published: October 9, 2019
Vulnerability identifier: #VU21684
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1166
CWE-ID: CWE-300
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to tamper with the NTLM exchange.
The vulnerability exists due to insufficient integrity check for NTLM packets. A remote attacker can modify flags of the NTLM packet without invalidating the signature and bypass the NTLM MIC (Message Integrity Check) protection.
Affected software
Microsoft Windows
Windows Server
Windows Server
How to mitigate CVE-2019-1166
Install updates from vendor's website.