Patch Repository

MS14-068 Bulletin Details
Bulletin ID MS14-068
Title Vulnerability in Kerberos Could Allow Elevation of Privilege (3011780)
Summary This security update resolves a privately reported vulnerability in Microsoft Windows Kerberos KDC that could allow an attacker to elevate unprivileged domain user account privileges to those of the domain administrator account. An attacker could use these elevated privileges to compromise any computer in the domain, including domain controllers. An attacker must have valid domain credentials to exploit this vulnerability. The affected component is available remotely to users who have standard user accounts with domain credentials; this is not the case for users with local account credentials only. When this security bulletin was issued, Microsoft was aware of limited, targeted attacks that attempt to exploit this vulnerability.
Knowledgebase 3011780

List of Patches

S.No Patch Description Severity
.Security Update for Windows Server 2003 (KB3011780)Critical
.Security Update for Windows Server 2003 x64 Edition (KB3011780)Critical
.Security Update for Windows Server 2008 R2 x64 Edition (KB3011780)Critical

Disclaimer: This webpage is intended to provide you information about patch announcement for certain specific software products. The information is provided "As Is" without warranty of any kind. The links provided point to pages on the vendors websites. You can get more information by clicking the links to visit the relevant pages on the vendors website.