SB2019021321 - Privilege escalation in implementation of Microsoft Kerberos TGT delegation
Published: February 13, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: N/A)
The vulnerability allows a remote attacker to escalate privileges within the domain.
A security issue exists in the way Ticket-Granting Tickets (TGT) are processed within the Active Directory forests.A remote attacker can acquire a TGT from a domain with an inbound trust and use it to escalate privileges within a neighbor forest.
Successful exploitation of the vulnerability requires that TGT delegation is enabled.
Remediation
Install update from vendor's website.