#VU17652 Permissions, Privileges, and Access Controls in Windows and Windows Server
Published: February 13, 2019
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to escalate privileges within the domain.
A security issue exists in the way Ticket-Granting Tickets (TGT) are processed within the Active Directory forests.A remote attacker can acquire a TGT from a domain with an inbound trust and use it to escalate privileges within a neighbor forest.
Successful exploitation of the vulnerability requires that TGT delegation is enabled.
Remediation
etdom.exe trust fabrikam.com /domain:contoso.com /EnableTGTDelegation:No