7.5
CVE-2026-50508
- EPSS 8.68%
- Veröffentlicht 09.06.2026 17:17:50
- Zuletzt bearbeitet 23.07.2026 08:10:00
- Erkennungen
Windows NTLM Spoofing Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1607 HwPlatform x64 Version < 10.0.14393.9234
Microsoft ≫ Windows 10 1607 HwPlatform x86 Version < 10.0.14393.9234
Microsoft ≫ Windows 11 22h2 HwPlatform arm64 Version < 10.0.22631.7219
Microsoft ≫ Windows 11 22h2 HwPlatform x64 Version < 10.0.22631.7219
Microsoft ≫ Windows Server 2004 HwPlatform x64 Version < 10.0.19045.7417
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016 Version < 10.0.14393.9234
Microsoft ≫ Windows Server 2022 Version < 10.0.20348.5256
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 8.68% | 0.946 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| Microsoft | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50508