H3-2023-0010
Kerberos Constrained Delegation
Category | SECURITY_MISCONFIGURATION |
Base Score | 4.9 |
Description
An Active Directory Principal (e.g. a User, Machine, or Service Account) can impersonate any unprotected domain principal when connecting to a specific service.
Impact
If an attacker obtains authentication material for the principal with Constrained Delegation, the attacker could impersonate a domain administrator on the target host -- enabling Host Compromise and possibly Domain Compromise if the target host is a high value target such as a Domain Controller.