← back
CVE-2014-6324

CVE-2014-6324

CVSS 8.8 HIGHEPSS 87.4%● KEV
In short

A flaw in Windows Kerberos authentication allows someone already logged into a domain to forge tickets and trick the system into granting them administrator-level access. This is dangerous because it lets attackers escalate their privileges without needing additional credentials.

Technical detail

The KDC in affected Windows versions fails to properly validate checksum signatures in Kerberos tickets, allowing authenticated domain users to forge valid tickets with elevated privileges. An attacker with valid domain credentials can craft a malicious ticket to impersonate an administrator and gain domain-level access without further authentication.

Summary generated and translated by AI from the official description.
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka "Kerberos Checksum Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →