vendor:
Windows
by:
Unknown
5.5
CVSS
MEDIUM
Elevation of Privilege
264
CWE
Product Name: Windows
Affected Version From: Windows 10 1803
Affected Version To: Windows 10 1809
Patch Exists: NO
Related CWE:
CPE: o:microsoft:windows_10:1803 and cpe:/o:microsoft:windows_10:1809
Platforms Tested: Windows 10 1803/1809
2021
Windows: SSPI Network Authentication Session 0 EoP
Performing an NTLM authentication to the same machine results in a network token which can be used to create arbitrary processes in session 0.
Mitigation:
Ensure proper authentication and authorization mechanisms are in place. Apply patches and updates provided by the vendor.