PT-2021-5121 · Microsoft+1 · Windows Server+3

·

CVE-2021-42287

·

Published

2021-11-09

·

Updated

2026-09-09

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Active Directory Domain Services (affected versions not specified)
Description An elevation-of-privilege issue exists due to insecure privilege management. A remote attacker can exploit this by abusing the Kerberos Privilege Attribute Certificate (PAC), which is a component that stores user authorization information, group memberships, and security attributes attached to a Kerberos ticket. This allows the attacker to impersonate domain controllers and gain elevated privileges on the system.
Recommendations Install Microsoft update KB5008380 to ensure the implementation of new PAC data structures, specifically PAC ATTRIBUTES INFO and PAC REQUESTOR, which enable the Key Distribution Center (KDC) to verify that the client name in the ticket resolves to the Security Identifier (SID) included in the PAC.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2581
ALT-PU-2022-2677
ALT-PU-2022-2866
ALT-PU-2022-2892
ALT-PU-2023-1656
ALT-PU-2024-14683
BDU:2021-05914
CVE-2021-42287

Affected Products

Alt Linux
Active Directory Domain Services
Windows Server
Windows