Impact
This vulnerability exposes sensitive information through Windows NTLM authentication, permitting an attacker to spoof authentication over a network and impersonate legitimate machines or users. The effect is a loss of confidentiality and potential unauthorized access, matching CWE-200.
Affected Systems
Microsoft Windows 10 1607, Windows 11 22H2, Windows Server 2012, 2012 R2, 2016, 2022, and Windows Server 2004 are affected across both x86 and arm64 platforms as specified in the CNA affected‑version list.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely a network‑based, unauthenticated attacker who can send NTLM traffic and receive spoofed responses, allowing impersonation of other endpoints on the same network.
OpenCVE Enrichment