Vulnerability Bulletins |
IBM Security Bulletin: Badlock Samba vulnerability issue on IBM Storwize V7000 Unified (CVE-2016-2118) |
|
| Affected software | IBM |
|
Badlock is a loophole that affects Windows and Samba systems/client. Badlock for Samba is referenced by CVE-2016-2118 (SAMR and LSA man in the middle attacks possible) and for Windows by CVE-2016-0128 / MS16-047 (Windows SAM and LSAD Downgrade Vulnerability). When Samba is configured as Domain Controller it allows remote attackers to spoof the computer name of a secure channel’s endpoints, and obtain sensitive session information, by running a crafted application and leveraging the More info: https://www.ibm.com/blogs/psirt/ibm-security-bulletin-badlock-samba-vulnerability-issue-on-ibm-storwize-v7000-unified-cve-2016-2118/ |
|






