#VU22718 Improper Authentication in Windows and Windows Server - CVE-2019-1384
Published: November 13, 2019
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the NETLOGON message is able to obtain the session key and sign messages. A remote authenticated attacker can send a specially crafted authentication request, bypass authentication process and gain unauthorized access to another machine using the original user privileges.