CVE-2024-43639: Remote Code Execution in Microsoft Windows KDC Proxy
ID: 54afc5c4-0cc3-579e-aaf7-85cd0fcc8ef5
STIX ID: report--54afc5c4-0cc3-579e-aaf7-85cd0fcc8ef5
Feed Name: Zero Day Initiative (ZDI) Blog
This report analyzes an ASN.1 integer-overflow and heap-buffer-overflow vulnerability in Microsoft's KDC Proxy (KPSSVC) that allows a remote, unauthenticated attacker to cause arbitrary code execution by sending specially crafted Kerberos responses with oversized length prefixes; it provides exploitation details, detection guidance (inspect TCP port 88 4-byte length prefixes), notes the vendor patch (CVE-2024-43639, Nov patch), and states the issue only affects systems using KDC Proxy and that no in-the-wild attacks have been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
