Permissions, Privileges, and Access Controls in Windows Server - CVE-2022-33679
Published: September 13, 2022 / Updated: November 30, 2022
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in the Windows Kerberos. A remote attacker can perform a man-in-the-middle attack, leading to security restrictions bypass and privilege escalation.
Affected software
How to mitigate CVE-2022-33679
Links to Public Exploits and PoC-codes
- Exploit #8638 - CVE-2022-33679 (One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html) (November 30, 2022)
- Exploit #8572 - CVE-2022-33679 (poc of CVE-2022-33679) (November 4, 2022)
- Exploit #8570 - CVE-2022-33679 (poc of CVE-2022-33679) (November 3, 2022)