Man-in-the-Middle (MitM) attack in Microsoft Windows and Windows Server - CVE-2019-1338

 

Man-in-the-Middle (MitM) attack in Microsoft Windows and Windows Server - CVE-2019-1338

Published: October 9, 2019


Vulnerability identifier: #VU21685
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1338
CWE-ID: CWE-300
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to tamper with the NTLMv2 exchange.

The vulnerability exists due to insufficient integrity check for NTLMv2 packets, when the client is also sending LMv2 responses. A remote attacker with ability to modify NTLM traffic exchange can bypass the NTLMv2 protection and gain the ability to downgrade NTLM security features.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2019-1338

Install updates from vendor's website.


External References

Related Security Bulletins