CVE-2020-16996
MEDIUMWindows Server 2012, 2016, 2019 - Kerberos Security Feature Bypass
Title source: llmDescription
Kerberos Security Feature Bypass Vulnerability
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
patch
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-16996
Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16996
Scores
CVSS v3
6.5
EPSS
0.0254
EPSS Percentile
83.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
Status
published
Products (20)
Microsoft/Windows Server 2012
6.2.9200.0 - 6.2.9200.23298
Microsoft/Windows Server 2012 (Server Core installation)
6.2.9200.0 - 6.2.9200.23298
Microsoft/Windows Server 2012 R2
6.3.9600.0 - 6.3.9600.19968
Microsoft/Windows Server 2012 R2 (Server Core installation)
6.3.9600.0 - 6.3.9600.19968
Microsoft/Windows Server 2016
10.0.14393.0 - 10.0.14393.4283
Microsoft/Windows Server 2016 (Server Core installation)
10.0.14393.0 - 10.0.14393.4283
Microsoft/Windows Server 2019
10.0.17763.0 - 10.0.17763.1817
Microsoft/Windows Server 2019 (Server Core installation)
10.0.17763.0 - 10.0.17763.1817
Microsoft/Windows Server version 2004
10.0.0 - 10.0.19043.867
Microsoft/Windows Server version 20H2
10.0.0 - 10.0.19043.867
... and 10 more
Published
Dec 10, 2020
Tracked Since
Feb 18, 2026