CVE-2020-15931: Infoleak
Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a Domain Controller.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15931?
CVE-2020-15931 is a vulnerability in Netwrix Account Lockout Examiner before version 5.1 that allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator.
What is the severity of CVE-2020-15931?
CVE-2020-15931 has a severity rating of 7.5 (high).
How does CVE-2020-15931 work?
CVE-2020-15931 works by generating a single Kerberos Pre-Authentication Failed (ID 4771) event to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator.
What software is affected by CVE-2020-15931?
Netwrix Account Lockout Examiner before version 5.1 is affected by CVE-2020-15931.
Is there a fix for CVE-2020-15931?
Yes, updating Netwrix Account Lockout Examiner to version 5.1 or above will fix CVE-2020-15931.