VDB

GCVE-110-CERTCC-2015-672268

GCVE-110-CERTCC-2015-672268
Advisory PublishedCVSS 6.3/10
Vulnetix · Advisory published April 13, 2015
Software running on Microsoft Windows that utilizes HTTP requests can be forwarded to a file:// protocol on a malicious server, which causes Windows to automatically attempt authentication via SMB to the malicious server in some circumstances. The encrypted form of the user's credentials are then logged on the malicious server. This vulnerability is alternatively known as "Redirect to SMB".

Risk Scores

CVSS 2.0
6.3/10
Medium · AV:N/AC:M/Au:S/C:C/I:N/A:N
certcc-cam
certcc-cam
impact0population0exploitation0widely_known0score_current0ease_of_exploitation0
certcc-vrda
certcc-vrda
d1_impact4d1_population4d1_direct_report1
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score5.7remediation_levelWreport_confidenceCenvironmental_score5.6836455144target_distributionHenvironmental_vectorCDP:ND/TD:H/CR:ND/IR:ND/AR:ND

References

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›