Tag
#Windows DPAPI (Data Protection Application Programming Interface)
CVE-2023-36004: Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
**What is the attack vector for this vulnerability?** To exploit this vulnerability, an attacker would need to launch a man-in-the-middle (MiTM) attack against the traffic passing between a domain controller and the target machine.
CVE-2022-34723: Windows DPAPI (Data Protection Application Programming Interface) Information Disclosure Vulnerability
**What type of information could be disclosed by this vulnerability?** An attacker who successfully exploited this vulnerability could view the data protection API (DPAPI) master key.