H3-2022-0097¶
Kerberos Pass-the-Ticket Attack
| Category | SECURITY_MISCONFIGURATION |
| Base Score | 9.8 |
Description¶
Compromised Ticket-Granting-Ticket or Ticket-Granting-Service tickets are used by attackers to access domain services.
Impact¶
Attackers can use stolen or forged tickets to move laterally within an environment bypassing normal system access controls.