SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-2374

The Netlogon service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2 does not properly implement domain-controller communication, which allows remote attackers to discover…

LOW 3.3EPSS 4.97%

Does this matter?

Lower severity and a low EPSS score (4.97%). Track it; it rarely justifies an emergency change on its own.

Description

The Netlogon service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2 does not properly implement domain-controller communication, which allows remote attackers to discover credentials by leveraging certain PDC access and spoofing the BDC role in a PDC communication channel, aka "Elevation of Privilege Vulnerability in Netlogon."

CVSS 2.0
3.3 LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
EPSS
4.97% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
microsoft/windows 2003 server · microsoft/windows server 2008 · microsoft/windows server 2012
Source
secure@microsoft.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.