CVE Published: 10/02/2011 |
CVE Updated: 06/08/2024 |
CVE Year: 2011 Source: microsoft |
Vendor: n/a |
Product: n/a Status : PUBLISHED
CVE-2011-0091 Description
Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."