Man-in-the-Middle (MitM) attack in Microsoft Windows and Windows Server - CVE-2019-1166

 

Man-in-the-Middle (MitM) attack in Microsoft Windows and Windows Server - CVE-2019-1166

Published: October 9, 2019


Vulnerability identifier: #VU21684
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1166
CWE-ID: CWE-300
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to tamper with the NTLM exchange.

The vulnerability exists due to insufficient integrity check for NTLM packets. A remote attacker can modify flags of the NTLM packet without invalidating the signature and bypass the NTLM MIC (Message Integrity Check) protection.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2019-1166

Install updates from vendor's website.


External References

Related Security Bulletins