NVD

Id
22548  
Name
CVE-2015-0006  
Description
The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to trigger an unintended permissive configuration by spoofing DNS and LDAP responses on a local network, aka "NLA Security Feature Bypass Vulnerability."  
Reject
 
CVSS Version
2  
CVSS Score
6.1  
Severity
Medium  
CVSS Base Score
6.1  
CVSS Impact Subscore
6.9  
CVSS Exploit Subscore
6.5  
CVSS Vector
(AV:A/AC:L/Au:N/C:N/I:C/A:N)  
Pub Date
2017-01-19  
Published
2015-01-13  
Modified Date
2017-01-02  
Seq
2015-0006  

Actions