Skip to content

H3-2021-0038

Kerberoasting

Category SECURITY_MISCONFIGURATION
Base Score 7.5

Description

Kerberoasting is an attacker technique that exploits weaknesses inherent to the Kerberos protocol. This technique enables an attacker with a low-privilege domain user account to retrieve password hashes for higher-privilege service accounts.

Impact

An attacker who's able to crack the password hash of a Kerberoastable service account will be able to escalate his or her privileges to those of the service account.

References