Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a Domain Controller.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-10-20T19:23:17
Updated: 2024-08-04T13:30:23.305Z
Reserved: 2020-07-24T00:00:00
Link: CVE-2020-15931
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2020-10-20T20:15:14.787
Modified: 2021-07-21T11:39:23.747
Link: CVE-2020-15931
Redhat
No data.