← back
CVE-2024-38239

Windows Kerberos Elevation of Privilege Vulnerability

CVSS 7.2 HIGHEPSS 1.7%CWE-1390
In short

A flaw in Windows Kerberos authentication allows an attacker with local access to escalate their privileges to a higher level of system access. This is dangerous because it lets an unprivileged user gain administrative control over the computer.

Technical detail

An elevation of privilege vulnerability exists in the Windows Kerberos implementation (CWE-1390) where improper validation or handling of Kerberos tokens permits a locally authenticated attacker to bypass privilege restrictions. The attack requires prior local system access and successful exploitation results in unauthorized privilege escalation to SYSTEM or domain administrator context.

Summary generated and translated by AI from the official description.
Windows Kerberos Elevation of Privilege Vulnerability
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →