#VU4848 Improper Authentication in Windows and Windows Server - CVE-2016-0049
Published: February 9, 2016 / Updated: April 7, 2020
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to bypass authentication process.
The vulnerability exists due to security feature bypass in Windows when Kerberos fails to check
the password change of a user signing into a workstation.
An attacker could bypass Kerberos authentication by connecting a
workstation to a malicious Kerberos Key Distribution Center (KDC) and gain access to sensitive data.