#VU21685 Man-in-the-Middle (MitM) attack in Windows and Windows Server - CVE-2019-1338
Published: October 9, 2019
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to tamper with the NTLMv2 exchange.
The vulnerability exists due to insufficient integrity check for NTLMv2 packets, when the client is also sending LMv2 responses. A remote attacker with ability to modify NTLM traffic exchange can bypass the NTLMv2 protection and gain the ability to downgrade NTLM security features.