Severity | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE ID | N/A |
CVSSv3 |
5.6 [CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N/E:U/RL:W/RC:C] |
CWE ID |
CWE-264 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
Windows Windows Server |
Vulnerable software versions |
Windows 8.1 Windows 7 Windows 10 Show more Windows Server 2012 Windows Server 2012 R2 Windows Server 2008 Show more |
Vendor URL | Microsoft |
The vulnerability allows a remote attacker to escalate privileges within the domain.
A security issue exists in the way Ticket-Granting Tickets (TGT) are processed within the Active Directory forests.A remote attacker can acquire a TGT from a domain with an inbound trust and use it to escalate privileges within a neighbor forest.
Successful exploitation of the vulnerability requires that TGT delegation is enabled.
etdom.exe trust fabrikam.com /domain:contoso.com /EnableTGTDelegation:No
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV190006