CVE-2016-0049
MEDIUMMicrosoft Windows Kerberos - Authentication Bypass via Crafted KDC
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2016-0049. PoCs published by Nabeel Ahmed, JackOfMostTrades.
AI-analyzed exploit summary This is a detailed technical writeup describing a Kerberos security feature bypass vulnerability (CVE-2016-0049) that allows an attacker with physical access to bypass authentication on a domain-joined Windows system with BitLocker enabled. The exploit involves creating a rogue domain controller and manipulating Active Directory objects to trick the target system into accepting a new password.
Description
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which allows remote attackers to bypass authentication by deploying a crafted Key Distribution Center (KDC) and then performing a sign-in action, aka "Windows Kerberos Security Feature Bypass."
Exploits (2)
This is a detailed technical writeup describing a Kerberos security feature bypass vulnerability (CVE-2016-0049) that allows an attacker with physical access to bypass authentication on a domain-joined Windows system with BitLocker enabled. The exploit involves creating a rogue domain controller and manipulating Active Directory objects to trick the target system into accepting a new password.
This repository contains a proof-of-concept exploit for CVE-2015-6095, which allows bypassing the Windows login screen via domain authentication manipulation. It includes scripts to set up malicious DNS, KDC, LDAP, and NetBIOS servers to facilitate the attack.
References (5)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N