Windows KDC Proxy Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? An unauthenticated attacker could use a specially crafted application to leverage a cryptographic protocol vulnerability in Windows Kerberos to perform remote code execution against the target.
Is KDC Proxy Server service (KPSSVC) a dependency of KKDCP? The vulnerability only exists on the KPSSVC server. We recommend that instances of KPSSVC server be patched immediately. Must KPSSVC be running for KKDCP to be enabled and functional? Yes. Will KPSSVC be started on-demand? No. You are only vulnerable if you are already using KPSSVC in your environment. KPSSVC is an additional feature Microsoft has been providing since Windows Server 2012. If you do not have it configured in your environment, then this vulnerability is not exploitable.
Are all Windows Servers affected by this vulnerability? This vulnerability only affects Windows Servers that are configured as a [MS-KKDCP]: Kerberos Key Distribution Center (KDC) Proxy Protocol server. Domain controllers are not affected.
🎯 Affected products13
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
- Windows Server 2022, 23H2 Edition (Server Core installation)
- Windows Server 2025
- Windows Server 2025 (Server Core installation)
✅ Remediation
KB5046617 (Security Update) — fixed build 10.0.26100.2314 KB5046696 (SecurityHotpatchUpdate) — fixed build 10.0.26100.2240 KB5046615 (Security Update) — fixed build 10.0.17763.6532 KB5046616 (Security Update) — fixed build 10.0.20348.2849 KB5046698 (SecurityHotpatchUpdate) — fixed build 10.0.20348.2819 KB5046618 (Security Update) — fixed build 10.0.25398.1251 KB5046612 (Security Update) — fixed build 10.0.14393.7515 KB5046697 (Monthly Rollup) — fixed build 6.2.9200.25165 KB5046682 (Monthly Rollup) — fixed build 6.3.9600.22267
🔗 References (19)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43639
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5046617
- referencehttps://support.microsoft.com/help/5046617
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5046696
- referencehttps://support.microsoft.com/help/5046696
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5046615
- referencehttps://support.microsoft.com/help/5046615
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5046616
- referencehttps://support.microsoft.com/help/5046616
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5046698
- referencehttps://support.microsoft.com/help/5046698
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5046618
- referencehttps://support.microsoft.com/help/5046618
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5046612
- referencehttps://support.microsoft.com/help/5046612
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5046697
- referencehttps://support.microsoft.com/help/5046697
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5046682
- referencehttps://support.microsoft.com/help/5046682