logo

New Kerberos Relay Technique Exploits DNS CNAMEs to Bypass Existing Defenses

ID: c66dcb36-8b31-54b0-9194-35548d0b66e1

STIX ID: report--c66dcb36-8b31-54b0-9194-35548d0b66e1

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-19

Date Updated: 2026-04-22

Author: Divya

...
...

This report describes CVE-2026-20929, a critical Windows Kerberos authentication relay vulnerability where attackers who can intercept DNS queries (via ARP/DHCP poisoning or similar MITM techniques) return crafted CNAME/A records to coerce victims into requesting Kerberos service tickets for attacker-controlled SPNs, enabling lateral movement and privilege escalation. The technique's cross-protocol ticket acceptance (e.g., HTTP <> SMB) greatly expands exploitation opportunities. Microsoft acknowledged the behavior and rolled out Channel Binding Token support for HTTP.sys in January 2026, while recommended mitigations include enforcing SMB signing, requiring CBT for HTTP/HTTPS, LDAP signing/LDAPS CBT, and DNS hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.