The Websense Security Labs team is aware of a recent discovery that provides attackers with the potential to intercept sensitive user credentials (username, domain, and hashed password) The attack relies on an end user being directed to, and authenticating against, an attacker-controlled SMB server. The issue has been assigned designation VU#672268. No attacks have been seen in the wild at the time of this writing but the implications of the vulnerability are suitably severe to warrant a triage of the issue.”]

