VU#813296: Microsoft Windows and Samba may allow spoofing of authenticated users ("Badlock")

The Security Account Manager Remote(SAMR)and Local Security Authority(Domain Policy)(LSAD)protocols do not properly establish Remote Procedure Call(RPC)channels,which may allow any attacker to impersonate an authenticated user or gain access to the SAM database,or launch denial of service attacks. This vulnerability is also known publicly as"Badlock". Continue reading VU#813296: Microsoft Windows and Samba may allow spoofing of authenticated users ("Badlock")

Badlock Vulnerability Clues Few and Far Between

Admins have to hold their breath for two more weeks on the Badlock vulnerability. Which will come first: the patch, or a public exploit? Continue reading Badlock Vulnerability Clues Few and Far Between