CVE-2015-0006

Published Jan 13, 2015

Last updated 6 years ago

Overview

Description
The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to trigger an unintended permissive configuration by spoofing DNS and LDAP responses on a local network, aka "NLA Security Feature Bypass Vulnerability."
Source
secure@microsoft.com
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
6.1
Impact score
6.9
Exploitability score
6.5
Vector string
AV:A/AC:L/Au:N/C:N/I:C/A:N

Weaknesses

nvd@nist.gov
CWE-264

Configurations