Junglewise Threat Intelligence

CVE-2014-6324: Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability

CVE-2014-6324 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-25

Technologies: Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows 8.1, Microsoft Windows Server 2003, Microsoft Windows Server 2012, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

The Kerberos Key Distribution Center (KDC) in multiple Microsoft Windows operating systems fails to properly validate signatures in tickets. A remote authenticated domain user can exploit this by forging a signature to elevate their privileges to domain administrator.

Affected products

  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8 Gold
  • Microsoft Windows 8.1 Gold
  • Microsoft Windows Server 2012 Gold, R2

Timeline

  • 2014-11-18: disclosed: Initial disclosure and technical details provided by Microsoft.
  • 2014-11-01: exploited: Exploitation in the wild reported to have occurred in November 2014.
  • 2014-11-18: patched: Microsoft released security bulletin MS14-068 to address the vulnerability.
  • 2022-03-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.