CVE-2020-17049: Kerberos KDC Security Feature Bypass Vulnerability
A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD). To exploit the vulnerability, a compromised service that is configured to use KCD could tamper with a service ticket that is not valid for delegation to force the KDC to accept it.
Other sources
Kerberos Security Feature Bypass Vulnerability
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-17049?
CVE-2020-17049 is a Kerberos Security Feature Bypass Vulnerability.
What software is affected by CVE-2020-17049?
Microsoft Windows Server 2012, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2016, Microsoft Windows Server 2019, and Samba versions 4.1.0 to 4.15.0 are affected by CVE-2020-17049.
How severe is CVE-2020-17049?
CVE-2020-17049 has a severity rating of 7.2 (out of 10).
What is the Common Weakness Enumeration (CWE) for CVE-2020-17049?
The CWE for CVE-2020-17049 is CWE-863.
How can I learn more about CVE-2020-17049?
You can find more information about CVE-2020-17049 in the references provided: Openwall, Microsoft Security Guidance Advisory, and Gentoo GLSA.