Impact
Zeek versions before 8.0.9 contain a null pointer dereference in the Kerberos protocol analyzer. The flaw is caused by the proc_padata() routine dereferencing an uninitialized pa_data_element field when parsing a KRB_ERROR message with error-code 25 (KDC_ERR_PREAUTH_REQUIRED) that includes a PA-DATA element of padata-type 2, 3, 11, or 19. The result is a crash of the sensor, leading to a denial of service. This weakness is classified as CWE‑476.
Affected Systems
All Zeek (Zeek) deployments running any version earlier than 8.0.9 that have the Kerberos analyzer enabled are affected. The vulnerability is triggered by traffic to UDP or TCP port 88, the standard Kerberos service port.
Risk and Exploitability
The CVSS score of 8.7 classifies this issue as high severity. The EPSS score of < 1% indicates a very low probability of exploitation, yet the exploitation path involves only a single UDP or TCP packet sent to port 88, with no credentials or prior authentication. The vulnerability is not listed in CISA’s KEV catalog, and the exploit is publicly available. Administrators should view this as an immediate risk to availability and prioritize remediation.
OpenCVE Enrichment