Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka Kerberos Spoofing Vulnerability.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Windows_7 | Microsoft | - (including) | - (including) |
Windows_server_2008 | Microsoft | r2 (including) | r2 (including) |