CVE-2014-6324
CVE-2014-6324
CVSS 8.8 HIGHEPSS 87.4%● KEV
Vexday Risk Score
100Fix now
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 8.8EPSS 87.4%KEV simPoC públicaNuclei —Metasploit simPatch referenciado
Lifecycle
18 Nov 2014Metasploit module available
18 Nov 2014Published on NVD
05 Dec 2014Public PoC
25 Mar 2022Active exploitation (CISA KEV)
Recommendation: Patch as soon as possible — active exploitation confirmed.
Who exploits it — 1
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
In short
A flaw in Windows Kerberos authentication allows someone already logged into a domain to forge tickets and trick the system into granting them administrator-level access. This is dangerous because it lets attackers escalate their privileges without needing additional credentials.
Technical detail
The KDC in affected Windows versions fails to properly validate checksum signatures in Kerberos tickets, allowing authenticated domain users to forge valid tickets with elevated privileges. An attacker with valid domain credentials can craft a malicious ticket to impersonate an administrator and gain domain-level access without further authentication.
Summary generated and translated by AI from the official description.
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka "Kerberos Checksum Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.