ZeroHour

CVE-2014-6324

KEVmass

Privilege Escalation in Microsoft Kerberos Key Distribution Center (KDC)

CISA: Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability

CVSS
EPSS
87%p100
Published
KEV added
AI analysis

CVE-2014-6324 is a privilege escalation flaw in the Kerberos Key Distribution Center (KDC) on Microsoft domain controllers: a remote, authenticated domain user sends specially crafted Kerberos ticket data that the KDC fails to validate correctly, allowing the attacker to obtain domain administrator privileges. An attacker who already holds any valid domain credentials can therefore escalate to full control of the Active Directory domain, which typically means compromise of every domain controller and every account in the forest. Any organization running Active Directory on Windows domain controllers is affected; the provided data does not enumerate specific Windows versions or the fixed release. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25, ransomware use unknown), carries a 87.4% EPSS probability of exploitation within 30 days (100th percentile), and is publicly associated in security reporting with the Duqu 2.0 espionage platform.

What to do: Apply the Microsoft security update for this vulnerability (MS14-068, November 2014) per vendor instructions on every domain controller, and verify no unpatched DC remains, since one vulnerable domain controller is enough for any domain user to become domain administrator. Prioritize internet-exposed and domain-controller assets in CISA KEV-driven patch tracking, and monitor Kerberos ticket traffic for anomalous or forged ticket/PAC content while patching is pending.

Affected
Microsoft Kerberos Key Distribution Center (KDC)
Estimated exposure
massmillions of Active Directory domain controllers / millions of domain users in scope (order-of-magnitude estimate) — The Kerberos KDC runs on every Windows domain controller and Active Directory is near-universal in Windows enterprise environments, so virtually every AD domain has affected infrastructure even though most domain controllers are not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.

CISA Known Exploited Vulnerability
Affected
Microsoft Kerberos Key Distribution Center (KDC)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Kerberos Key Distribution Center (KDC)
Weakness
CWE-264

In the news