CVE-2020-17049

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/11/2020
Last modified:
10/09/2024

Description

A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD).<br /> To exploit the vulnerability, a compromised service that is configured to use KCD could tamper with a service ticket that is not valid for delegation to force the KDC to accept it.<br /> The update addresses this vulnerability by changing how the KDC validates service tickets used with KCD.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:20h2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:1909:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:2004:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.1.0 (including) 4.13.13 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.14.0 (including) 4.14.9 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.15.0 (including) 4.15.1 (excluding)