logo

255 Insecure functionality - Pass the hash


Description

It is possible to use the Pass The Hash technique to access resources within the domain.


Impact

Use account hashes to access domain resources.


Recommendation

Implement monitoring policies to detect the use of lateral movement techniques such as Pass The Hash.


Threat

Attacker from internal network without authentication with domain user hashes.


Expected Remediation Time

60 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: A
  • Attack complexity: H
  • Attack Requirements: N
  • Privileges required: N
  • User interaction: N
  • Confidentiality (VC): H
  • Integrity (VI): H
  • Availability (VA): N
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Fixes


Last updated

2024/02/18