Kerberos Constrained Delegation Service Ticket Tampering Vulnerability

Kerberos Constrained Delegation Service Ticket Tampering Vulnerability

CVE-2020-17049 · MEDIUM Severity

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

<p>A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD).</p> <p>To exploit the vulnerability, a compromised service that is configured to use KCD could tamper with a service ticket that is not valid for delegation to force the KDC to accept it.</p> <p>The update addresses this vulnerability by changing how the KDC validates service tickets used with KCD.</p>

Learn more about our Web Application Penetration Testing UK.