Executive brief
The Windows Key Distribution Center (KDC) is a critical authentication service that manages Kerberos ticket generation and validation in enterprise networks. An out-of-bounds memory read vulnerability in this service allows an unauthenticated remote attacker to crash the KDC, disrupting authentication services across the domain and potentially preventing legitimate users from accessing network resources.
Technical details
An out-of-bounds read vulnerability exists in the Windows Key Distribution Center, a core component of the Kerberos authentication system. The vulnerability can be triggered by sending specially crafted network packets to the KDC service, requiring no authentication or user interaction. Exploitation results in denial of service through service crash or hang. The vulnerability is network-reachable and affects enterprise environments relying on Kerberos for domain authentication.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed