Skip to content

H3-2023-0010

Kerberos Constrained Delegation

Category SECURITY_MISCONFIGURATION
Base Score 4.9

Description

An Active Directory Principal (e.g. a User, Machine, or Service Account) can impersonate any unprotected domain principal when connecting to a specific service.

Impact

If an attacker obtains authentication material for the principal with Constrained Delegation, the attacker could impersonate a domain administrator on the target host -- enabling Host Compromise and possibly Domain Compromise if the target host is a high value target such as a Domain Controller.

References