Since the Windows Kerberos RC4-HMAC Elevation of...
Critical severity
Unreviewed
Published
Mar 7, 2023
to the GitHub Advisory Database
•
Updated Sep 26, 2023
Description
Published by the National Vulnerability Database
Mar 6, 2023
Published to the GitHub Advisory Database
Mar 7, 2023
Last updated
Sep 26, 2023
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
References