CVE-2024-38129: Windows Kerberos Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.5)
- CVSS Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2024-Oct
- Released
- 2024-10-08
- EPSS Score
- 2.00% (percentile: 83.7%)
FAQ
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment of the targeted component.
What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain domain administrator privileges.
Affected Products (1)
Windows
- Windows Server 2022, 23H2 Edition (Server Core installation)
Security Updates (1)
Revision History
- 2024-10-08: Information published.