MS14-068: Vulnerability in Kerberos Could Allow Elevation of Privilege (3011780) (ESKIMOROLL)

High Nessus Plugin ID 79311

Synopsis

The remote implementation of Kerberos KDC is affected by a privilege escalation vulnerability.

Description

The remote Windows host is affected by a privilege escalation vulnerability due to the Kerberos Key Distribution Center (KDC) implementation not properly validating signatures. A remote attacker can exploit this vulnerability to elevate an unprivileged domain user account to a domain administrator account.

ESKIMOROLL is one of multiple Equation Group vulnerabilities and exploits disclosed on 2017/04/14 by a group known as the Shadow Brokers.

Solution

Microsoft has released a set of patches for Windows 2003, Vista, 2008, 7, 2008 R2, 8, 2012, 8.1, and 2012 R2.

See Also

https://technet.microsoft.com/library/security/ms14-068

Plugin Details

Severity: High

ID: 79311

File Name: smb_nt_ms14-068.nasl

Version: 1.17

Type: local

Agent: windows

Published: 2014/11/18

Modified: 2018/08/03

Dependencies: 57033, 13855

Risk Information

Risk Factor: High

CVSSv2

Base Score: 9

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Temporal Vector: CVSS2#E:H/RL:OF/RC:C

CVSSv3

Base Score: 8.8

Temporal Score: 8.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/11/18

Vulnerability Publication Date: 2014/11/18

Exploitable With

CANVAS (CANVAS)

Core Impact

Reference Information

CVE: CVE-2014-6324

BID: 70958

CERT: 213119

IAVA: 2014-A-0180

MSFT: MS14-068

MSKB: 3011780