New Kerberos Relay Attack Uses DNS CNAME to Bypass Mitigations – PoC Released
ID: 1b720723-dcca-5542-a081-626ec70d2058
STIX ID: report--1b720723-dcca-5542-a081-626ec70d2058
Feed Name: cybersecurityNews.com
A critical Kerberos authentication weakness allows an on-path attacker to use DNS CNAME coercion to make Windows clients request service tickets for attacker-controlled SPNs, enabling credential relay attacks (including HTTP→SMB and HTTP→LDAP), lateral movement, impersonation, and potential RCE via ADCS Web Enrollment (ESC8). Researchers published a MITM6-based PoC with CNAME poisoning; Microsoft patched HTTP.sys (CVE-2026-20929) to mitigate HTTP relays, but the fundamental CNAME coercion primitive remains, leaving other protocols at risk. Organizations are advised to enforce SMB/LDAP signing, require Channel Binding Tokens and HTTPS with CBT, harden DNS infrastructure, and monitor anomalous TGS requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
