Learn about CVE-2017-11368, a vulnerability in MIT Kerberos 5 allowing authenticated attackers to disrupt the Key Distribution Center (KDC) by sending invalid requests. Find mitigation steps and prevention measures here.
MIT Kerberos 5 vulnerability allowing an authenticated attacker to induce a failure in the Key Distribution Center (KDC) by sending invalid requests.
Understanding CVE-2017-11368
An attacker authenticated in MIT Kerberos 5 version 1.7 or later can trigger a KDC failure by sending specific invalid requests.
What is CVE-2017-11368?
In MIT Kerberos 5 (krb5) 1.7 and later, an attacker with authentication privileges can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
The Impact of CVE-2017-11368
Technical Details of CVE-2017-11368
A vulnerability in MIT Kerberos 5 that allows an authenticated attacker to disrupt the KDC by sending specific invalid requests.
Vulnerability Description
The vulnerability in MIT Kerberos 5 (krb5) version 1.7 and later enables an attacker to cause a KDC assertion failure through invalid S4U2Self or S4U2Proxy requests.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Steps to address and prevent the CVE-2017-11368 vulnerability.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates