PT-2021-5121 · Microsoft+1 · Windows Server+3
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Active Directory Domain Services (affected versions not specified)
Description
An elevation-of-privilege issue exists due to insecure privilege management. A remote attacker can exploit this by abusing the Kerberos Privilege Attribute Certificate (PAC), which is a component that stores user authorization information, group memberships, and security attributes attached to a Kerberos ticket. This allows the attacker to impersonate domain controllers and gain elevated privileges on the system.
Recommendations
Install Microsoft update KB5008380 to ensure the implementation of new PAC data structures, specifically
PAC ATTRIBUTES INFO and PAC REQUESTOR, which enable the Key Distribution Center (KDC) to verify that the client name in the ticket resolves to the Security Identifier (SID) included in the PAC.Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Active Directory Domain Services
Windows Server
Windows