CVE-2024-26183

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 9, 2024
Updated: Jan 8, 2025
CWE ID 476

Summary

CVE-2024-26183 is a newly disclosed vulnerability affecting the Windows Kerberos protocol. This issue enables an attacker to cause a denial of service condition by sending specially crafted packets to a targeted system. The vulnerability exploits a flaw in the way Kerberos handles certain types of error messages, potentially leading to an infinite loop and exhaustion of system resources. The attack does not involve direct exploitation of user credentials or data theft. Microsoft has acknowledged the vulnerability and is working on a patch to address the issue. In the meantime, affected systems should be secured with appropriate mitigations to minimize the risk of a successful attack.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share