Junglewise Threat Intelligence

CVE-2026-47288: Microsoft Windows Kerberos integer overflow remote code execution

CVE-2026-47288 · Severity: high · CVSS 7.1 · Published 2026-06-09

Technologies: Microsoft Windows Kerberos. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Windows Kerberos, the primary system used for verifying user identities and securing logins across corporate networks. An authorized user on the same local network could exploit this flaw to run unauthorized commands or software on affected systems. This could lead to a complete takeover of the server or workstation, potentially compromising sensitive data and disrupting business operations.

Technical details

An integer overflow vulnerability (CWE-190) exists within the Microsoft Windows Kerberos implementation. The flaw is triggered during the processing of Kerberos authentication requests, where improper bounds checking leads to a memory corruption condition. An attacker must be authenticated (Low privileges) and positioned on an adjacent network to exploit the vulnerability. Successful exploitation allows for remote code execution (RCE) in the context of the Kerberos service. The attack complexity is rated as high, suggesting specific timing or environmental conditions are required for a successful exploit.

Affected products

  • Microsoft Windows Kerberos

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats