Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:16277
HistoryMay 02, 2019 - 5:13 a.m.

Privilege Escalation

2019-05-0205:13:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

EPSS

0.008

Percentile

81.9%

Kerberos is vulnerable to privilege escalation. The the MIT Kerberos administration server (kadmind) incorrectly accepted certain authentication requests for two-component server principal names. A remote attacker able to acquire a key with a particularly named principal (such as “kad/x”) could use this flaw to impersonate any user to kadmind, and perform administrative actions as that user.

References