MS.Windows.CredSSP.Man.in.the.Middle.Code.Execution

description-logoDescription

This indicates an attack attempt to exploit a Remote Code Execution Vulnerability in Microsoft Windows Server.
The vulnerability is due to an error in the vulnerable application when handling the CredSSP component during network level authentication. A remote attacker can exploit this to execute arbitrary code through a man in the middle attack by impersonating the server.

affected-products-logoAffected Products

Microsoft Windows 10
Microsoft Windows 10 Version 1511
Microsoft Windows 7
Microsoft Windows 8.1 for 32-bit Systems
Microsoft Windows 8.1 for x64-based Systems
Microsoft Windows RT 8.1
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2012 (Server Core)
Microsoft Windows Server 2012 R2 (Server Core)
Microsoft Windows Server 2016
Microsoft Windows Server 2016 Server Core
Microsoft Windows Server version 1709 (Server Core Installation)

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor:
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-0886

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)