First published: Wed Nov 11 2020(Updated: )
A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD). To exploit the vulnerability, a compromised service that is configured to use KCD could tamper with a service ticket that is not valid for delegation to force the KDC to accept it.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
=r2 | ||
=20h2 | ||
=1903 | ||
=1909 | ||
=2004 | ||
>=4.1.0<4.13.13 | ||
>=4.14.0<4.14.9 | ||
>=4.15.0<4.15.1 | ||
Microsoft Windows Server 2012 | ||
Microsoft Windows Server 2012 | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =20h2 | |
Microsoft Windows Server 2016 | =1903 | |
Microsoft Windows Server 2016 | =1909 | |
Microsoft Windows Server 2016 | =2004 | |
Microsoft Windows Server 2019 | ||
Samba Samba | >=4.1.0<4.13.13 | |
Samba Samba | >=4.14.0<4.14.9 | |
Samba Samba | >=4.15.0<4.15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17049 is a Kerberos Security Feature Bypass Vulnerability.
Microsoft Windows Server 2012, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2016, Microsoft Windows Server 2019, and Samba versions 4.1.0 to 4.15.0 are affected by CVE-2020-17049.
CVE-2020-17049 has a severity rating of 7.2 (out of 10).
The CWE for CVE-2020-17049 is CWE-863.
You can find more information about CVE-2020-17049 in the references provided: Openwall, Microsoft Security Guidance Advisory, and Gentoo GLSA.