Impact
The vulnerability is an improper authorization flaw in the Windows Kerberos authentication system that can let an attacker who is already authorized within a Windows domain increase privileges when communicating over adjacent networks. This weakness, classified as CWE‑285, means an adversary can gain higher privileges on the target network, potentially compromising the confidentiality, integrity, and availability of any services that rely on Kerberos authentication.
Affected Systems
Microsoft Windows Server operating systems from 2012 through 2025, including the 23H2 edition, and both full and Server‑Core installations, are affected. All 64‑bit builds of these server products contain the vulnerable Kerberos component.
Risk and Exploitability
The CVSS score of 8.0 indicates high severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. Attackers would need legitimate access within the same or an adjacent network and knowledge of Kerberos credentials to exploit this flaw, so the threat is primarily from authenticated insiders or compromised accounts. Until the vendor patch is applied, affected servers remain at risk of privilege escalation.
OpenCVE Enrichment