MS14-068: Vulnerability in Kerberos Could Allow Elevation of Privilege (3011780) (ESKIMOROLL)

High Nessus Plugin ID 79311


The remote implementation of Kerberos KDC is affected by a privilege escalation vulnerability.


The remote Windows host is affected by a privilege escalation vulnerability due to the Kerberos Key Distribution Center (KDC) implementation not properly validating signatures. A remote attacker can exploit this vulnerability to elevate an unprivileged domain user account to a domain administrator account.

ESKIMOROLL is one of multiple Equation Group vulnerabilities and exploits disclosed on 2017/04/14 by a group known as the Shadow Brokers.


Microsoft has released a set of patches for Windows 2003, Vista, 2008, 7, 2008 R2, 8, 2012, 8.1, and 2012 R2.

See Also

Plugin Details

Severity: High

ID: 79311

File Name: smb_nt_ms14-068.nasl

Version: $Revision: 1.14 $

Type: local

Agent: windows

Published: 2014/11/18

Modified: 2017/07/28

Dependencies: 13855, 57033

Risk Information

Risk Factor: High


Base Score: 9

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND


Base Score: 8.8

Temporal Score: 8.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:X

Vulnerability Information

CPE: cpe:/o:microsoft:windows

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/11/18

Vulnerability Publication Date: 2014/11/18

Exploitable With


Core Impact

Reference Information

CVE: CVE-2014-6324

BID: 70958

OSVDB: 114751

CERT: 213119

IAVA: 2014-A-0180

MSFT: MS14-068

MSKB: 3011780