PT-2024-1031 · Microsoft · Windows Kerberos+1

Ldwilmore34

·

Published

2024-01-09

·

Updated

2024-06-11

·

CVE-2024-20674

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Kerberos (affected versions not specified)
Description The vulnerability is related to a security feature bypass in the Windows Kerberos implementation, allowing an authenticated attacker to establish a machine-in-the-middle (MITM) attack or use other local network spoofing techniques to send a malicious Kerberos message to the client victim machine, spoofing itself as the Kerberos authentication server. This could allow attackers to bypass authentication. The issue is estimated to be critical, with potential for significant impact.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00240
CVE-2024-20674

Affected Products

Windows
Windows Kerberos