CVE-2024-20674: Windows Kerberos Security Feature Bypass Vulnerability
Windows Kerberos Security Feature Bypass Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22464Patch KB5034176 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26910Patch KB5034167 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.21765Patch KB5034171 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24664Patch KB5034184 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6614Patch KB5034119 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.643Patch KB5034130 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.3007Patch KB5034123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20402Patch KB5034134 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.3930Patch KB5034122 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.3007Patch KB5034123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.3930Patch KB5034122 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.5329Patch KB5034127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2227Patch KB5034129 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2713Patch KB5034121
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20674?
The severity of CVE-2024-20674 is considered critical as it allows attackers to bypass security features in the Kerberos authentication protocol.
How do I fix CVE-2024-20674?
To fix CVE-2024-20674, apply the security updates provided by Microsoft for the affected Windows versions.
Which Windows versions are affected by CVE-2024-20674?
CVE-2024-20674 affects various versions of Windows 10, Windows 11, and Windows Server, including specific builds like 21H2 and 22H2.
What impact does CVE-2024-20674 have on security?
CVE-2024-20674 may allow unauthorized access to sensitive information by bypassing security controls in the Kerberos authentication process.
Is there a workaround for CVE-2024-20674?
No official workaround exists for CVE-2024-20674; applying the security patches is the recommended action.