logo

CVE-2024-43639: Remote Code Execution in Microsoft Windows KDC Proxy

ID: 54afc5c4-0cc3-579e-aaf7-85cd0fcc8ef5

STIX ID: report--54afc5c4-0cc3-579e-aaf7-85cd0fcc8ef5

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
65/100

Date Published: 2025-03-04

Date Updated: 2026-05-01

Author: Trend Micro Research Team

...
...

This report analyzes an ASN.1 integer-overflow and heap-buffer-overflow vulnerability in Microsoft's KDC Proxy (KPSSVC) that allows a remote, unauthenticated attacker to cause arbitrary code execution by sending specially crafted Kerberos responses with oversized length prefixes; it provides exploitation details, detection guidance (inspect TCP port 88 4-byte length prefixes), notes the vendor patch (CVE-2024-43639, Nov patch), and states the issue only affects systems using KDC Proxy and that no in-the-wild attacks have been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.