Intrusion Prevention

MS.Windows.CredSSP.Man.in.the.Middle.Code.Execution

Description

This indicates an attack attempt to exploit a Remote Code Execution Vulnerability in Microsoft Windows Server.
The vulnerability is due to an error in the vulnerable application when handling the CredSSP component during network level authentication. A remote attacker can exploit this to execute arbitrary code through a man in the middle attack by impersonating the server.

Affected Products

Microsoft Windows 10
Microsoft Windows 10 Version 1511
Microsoft Windows 7
Microsoft Windows 8.1 for 32-bit Systems
Microsoft Windows 8.1 for x64-based Systems
Microsoft Windows RT 8.1
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2012 (Server Core)
Microsoft Windows Server 2012 R2 (Server Core)
Microsoft Windows Server 2016
Microsoft Windows Server 2016 Server Core
Microsoft Windows Server version 1709 (Server Core Installation)

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor:
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-0886

CVE References

CVE-2018-0886