CVE-2016-0128, also known as "BADLOCK," is a protocol-downgrade vulnerability affecting the SAM and LSAD protocol implementations across various Microsoft Windows versions, including Vista, Server 2008, 7, 8.1, Server 2012, RT 8.1, and 10. This flaw allows man-in-the-middle attackers to impersonate users by modifying client-server data streams due to improper RPC channel establishment. With a CVSS score of 6.8 (Medium), it requires high attack complexity and user interaction, but can lead to high confidentiality and integrity impacts. Despite its high FAUCET Risk Score of 97/100 and significant EPSS, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Community discussion and media coverage are limited, with only one article from SecurityWeek.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.