Vulnerability Bulletins

IBM Security Bulletin: Badlock Samba vulnerability issue on IBM Storwize V7000 Unified (CVE-2016-2118)

   
Affected software IBM
 
Badlock is a loophole that affects Windows and Samba systems/client. Badlock for Samba is referenced by CVE-2016-2118 (SAMR and LSA man in the middle attacks possible) and for Windows by CVE-2016-0128 / MS16-047 (Windows SAM and LSAD Downgrade Vulnerability). When Samba is configured as Domain Controller it allows remote attackers to spoof the computer name of a secure channel’s endpoints, and obtain sensitive session information, by running a crafted application and leveraging the

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-badlock-samba-vulnerability-issue-on-ibm-storwize-v7000-unified-cve-2016-2118/