Skip to main content

Microsoft Windows Kerberos Elevation of Privilege Vulnerability

Last Update Date: 27 Nov 2014 Release Date: 19 Nov 2014 3331 Views

RISK: High Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

A remote elevation of privilege vulnerability exists in implementations of Kerberos KDC in Microsoft Windows. The vulnerability exists when the Microsoft Kerberos KDC implementations fail to properly validate signatures, which can allow for certain aspects of a Kerberos service ticket to be forged. Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft was aware of limited, targeted attacks that attempt to exploit this vulnerability. Note that the known attacks did not affect systems running Windows Server 2012 or Windows Server 2012 R2. The update addresses the vulnerability by correcting signature verification behavior in Windows implementations of Kerberos.


Impact

  • Elevation of Privilege

System / Technologies affected

  • Windows Server 2003 
  • Windows Vista 
  • Windows Server 2008 
  • Windows 7 
  • Windows Server 2008 R2 
  • Windows 8 and Windows 8.1 
  • Windows Server 2012 and Windows Server 2012 R2

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link