CVE-2014-6324highunder attack

CVE-2014-6324

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA, has a working public exploit and 1 threat group(s) use it.

ssvc Actcvss 8.8epss 87%
from disclosure to weapon17 days
Published on NVDNov 18
1st PoC+17d
metasploitNov 18
CISA KEV+2684d
exploitation probability
87%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 group(s)1 public exploit(s)
Who exploits it — 1

Groups known to exploit this vulnerability (MITRE ATT&CK attribution).

Action required by CISAfederal deadline: 2022-04-15

Apply updates per vendor instructions.

In short

A flaw in Windows Kerberos authentication allows someone already logged into a domain to forge tickets and trick the system into granting them administrator-level access. This is dangerous because it lets attackers escalate their privileges without needing additional credentials.

Technical detail

The KDC in affected Windows versions fails to properly validate checksum signatures in Kerberos tickets, allowing authenticated domain users to forge valid tickets with elevated privileges. An attacker with valid domain credentials can craft a malicious ticket to impersonate an administrator and gain domain-level access without further authentication.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka "Kerberos Checksum Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.