CVE-2019-0734: Critical severity windows 10 vulnerability
An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this vulnerability by changing how these requests are validated., aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0936.
Affected Software
Remediation
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
Systems running the listed Microsoft Windows client, server, or RT versions are in scope. Exploitation requires an attacker to act as a man-in-the-middle for Kerberos authentication traffic; no prior privileges or user interaction are required.
What is the practical impact of successful exploitation?
A successful attacker can be validated as an Administrator, resulting in elevation of privilege with high impact to confidentiality, integrity, and availability.
What should be done to remediate the vulnerability?
Apply the available Microsoft security update. The provided information does not specify an alternative mitigation for systems that cannot yet be patched.