CVE-2014-6324
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka "Kerberos Checksum Vulnerability."
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 87% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
microsoft: windows 7; microsoft: windows 8; microsoft: windows 8.1; microsoft: windows server 2003; microsoft: windows server 2008; microsoft: windows server 2012
קישורים
- http://blogs.technet.com/b/srd/archive/2014/11/18/additional-information-about… Not ApplicableVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-… PatchVendor Advisory
- http://blogs.technet.com/b/srd/archive/2014/11/18/additional-information-about… Not ApplicableVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-… PatchVendor Advisory
- http://marc.info/?l=bugtraq&m=142350249315918&w=2 Mailing ListThird Party Advisory
- http://secunia.com/advisories/62556 Broken Link
- http://www.securityfocus.com/bid/70958 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1031237 Broken LinkThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/ncas/alerts/TA14-323A Third Party AdvisoryUS Government Resource
- http://marc.info/?l=bugtraq&m=142350249315918&w=2 Mailing ListThird Party Advisory