Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a Domain Controller.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-10-20T19:23:17
Updated: 2020-10-20T19:23:17
Reserved: 2020-07-24T00:00:00
Link: CVE-2020-15931
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-10-20T20:15:14.787
Modified: 2021-07-21T11:39:23.747
Link: CVE-2020-15931
JSON object: View
Redhat Information
No data.
CWE