CVE-2015-6095 describes a Kerberos security feature bypass in multiple versions of Microsoft Windows, including Vista, Windows 7, 8, 8.1, 10, and Server editions. This vulnerability, with a CVSS score of 4.9 (AV:L/AC:L/Au:N/C:N/I:C/A:N), allows physically proximate attackers to bypass authentication and conduct decryption attacks against BitLocker by connecting to an unintended Key Distribution Center. While the vulnerability has a low EPSS score and no known public exploits in Metasploit or ExploitDB, it has garnered significant media attention with two articles and two community mentions. The "Malicious Butler" attack, as it was dubbed, highlights the potential for a physically present attacker to exploit this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:C/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.