6.1

CVE-2015-0006

The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to trigger an unintended permissive configuration by spoofing DNS and LDAP responses on a local network, aka "NLA Security Feature Bypass Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 7 Version - Update sp1
Microsoft ≫ Windows 8 Version -
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2008 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Windows Server 2012 Version - Update gold
Microsoft ≫ Windows Server 2012 Version r2 SwPlatform x64
Microsoft ≫ Windows Vista Version - Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.61% 0.955
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 6.5 6.9
AV:A/AC:L/Au:N/C:N/I:C/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/62098
http://secunia.com/advisories/62184
http://www.securityfocus.com/bid/71930
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-005
https://exchange.xforce.ibmcloud.com/vulnerabilities/99521
https://exchange.xforce.ibmcloud.com/vulnerabilities/99522