PT-2020-4776 · Microsoft+7 · Active Directory+9

Jake Karnes

·

Published

2020-11-10

·

Updated

2024-09-10

·

CVE-2020-17049

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Windows versions prior to the fixed version
Description: A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD). To exploit the vulnerability, a compromised service that is configured to use KCD could tamper with a service ticket that is not valid for delegation to force the KDC to accept it. This issue is related to the Kerberos protocol used in Active Directory for authentication. The vulnerability allows an attacker to bypass existing security restrictions and gain unauthorized access to the application.
Recommendations: To resolve the issue, update the system to the latest version that includes the fix for this vulnerability. As a temporary workaround, consider restricting access to the Kerberos Constrained Delegation (KCD) feature until a patch is available. Avoid using service tickets that are not valid for delegation in the affected KDC until the issue is resolved. Apply the November updates released by Microsoft, which contain a patch for this vulnerability. Note that applying the patch may cause authentication issues on domain controllers with installed updates and without them or with very old versions of the operating system.

Fix

Incorrect Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ALSA-2023:2570
ALSA-2024:0143
ALT-PU-2021-3227
ALT-PU-2021-3296
ALT-PU-2021-3339
ALT-PU-2021-3470
AZL-10661
AZL-36992
BDU:2020-05328
CESA-2024_0143
CVE-2020-17049
OPENSUSE-SU-2024:11631-1
OPENSUSE-SU-2024:13200-1
RHSA-2023:2570
RHSA-2023_2570
RHSA-2024:0137
RHSA-2024:0139
RHSA-2024:0143
RHSA-2024:0252
RHSA-2024_0143
RLSA-2024:0143
SUSE-SU-2022:0361-1

Affected Products

Alt Linux
Active Directory
Almalinux
Centos
Kerberos
Red Hat
Rocky Linux
Samba
Suse
Windows