PT-2011-2040 · Microsoft · Windows Server 2003+3

Publicado

2011-02-10

·

Atualizado

2019-02-26

·

CVE-2011-0043

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows XP versions SP2 through SP3 Microsoft Windows Server 2003 version SP2
Description The issue concerns a weakness in the Kerberos implementation, specifically its support for weak hashing algorithms. This weakness can be exploited by a local user to gain elevated privileges on the system by operating a service that sends crafted service tickets. The vulnerability is related to the ability to forge certain aspects of a Kerberos service ticket, potentially allowing a malicious user to obtain a token with elevated privileges.
Recommendations For Microsoft Windows XP versions SP2 through SP3, consider disabling the use of weak hashing algorithms in Kerberos until a patch is available. For Microsoft Windows Server 2003 version SP2, restrict access to services that utilize Kerberos authentication to minimize the risk of exploitation. As a temporary workaround, consider configuring the system to use stronger hashing mechanisms for Kerberos service tickets until a fix is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-0043

Produtos afetados

Kerberos
Windows Server 2003
Windows Xp
Windows