logo

New Kerberos Relay Attack Uses DNS CNAME to Bypass Mitigations – PoC Released

ID: 1b720723-dcca-5542-a081-626ec70d2058

STIX ID: report--1b720723-dcca-5542-a081-626ec70d2058

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-19

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical Kerberos authentication weakness allows an on-path attacker to use DNS CNAME coercion to make Windows clients request service tickets for attacker-controlled SPNs, enabling credential relay attacks (including HTTP→SMB and HTTP→LDAP), lateral movement, impersonation, and potential RCE via ADCS Web Enrollment (ESC8). Researchers published a MITM6-based PoC with CNAME poisoning; Microsoft patched HTTP.sys (CVE-2026-20929) to mitigate HTTP relays, but the fundamental CNAME coercion primitive remains, leaving other protocols at risk. Organizations are advised to enforce SMB/LDAP signing, require Channel Binding Tokens and HTTPS with CBT, harden DNS infrastructure, and monitor anomalous TGS requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.