VOOZH about

URL: https://unit42.paloaltonetworks.com/cve-2020-17049/

⇱ CVE-2020-17049 AKA Bronze Bit Kerberos Vulnerability: Threat Brief


Vulnerabilities

Threat Brief: Kerberos KDC Security Feature Bypass Vulnerability (CVE-2020-17049 AKA Bronze Bit)

πŸ‘ Clock Icon
< 1 min read
Related Products

Executive Summary

A recent vulnerability in the Kerberos authentication protocol, CVE-2020-17049 (dubbed Bronze Bit), has been disclosed by Microsoft. The vulnerability is in the way that the Key Distribution Center (KDC) handles service tickets and validates whether delegation is allowed.

In the attack, as detailed in the Palo Alto Networks Security Operations blog, β€œProtecting Against the Bronze Bit Vulnerability with Cortex XDR,” the attacker tampers with the Kerberos service ticket, which allows the attacker to authenticate to the target as any user, including sensitive accounts and members of the β€œProtected Users” group.

Mitigation Actions for CVE-2020-17049

The vulnerability was patched by Microsoft, and the patch will be gradually deployed with upcoming Windows updates. Microsoft aims to enforce using the patch only on or after May 11, 2021.

Conclusion

Palo Alto Network customers running Cortex XDR version 7.3 with the latest content update are protected from β€œPass-the-Ticket” attacks using the standard Windows API. Customers running Cortex XDR Pro with analytics enabled will get alerted on related suspicious activities and specifically on a delegation from or to a protected user.

Palo Alto Networks will update this Threat Brief with new information and recommendations as they become available.

Additional Resources

Related Vulnerabilities Resources

Get updates from Unit 42

Peace of mind comes from staying ahead of threats. Subscribe today.

Get the latest news, invites to events, and threat alerts

Default Heading

Read the article πŸ‘ Right Arrow