CVE-2022-37966
vulnerability analysis and mitigation

Overview

The Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability (CVE-2022-37966) was discovered and addressed in November 2022. This security vulnerability affects Windows authentication systems, specifically related to the Kerberos protocol implementation. The vulnerability involves security bypass and elevation of privilege issues with Authentication Negotiation when using weak RC4-HMAC negotiation (Microsoft Support).

Technical details

The vulnerability affects the Windows Kerberos Key Distribution Center (KDC) and involves weak encryption types, particularly RC4-HMAC. After the security update, AES is set as the default encryption type for session keys on accounts that are not already marked with a default encryption type. The vulnerability can be identified through Active Directory queries that look for accounts where DES/RC4 is explicitly enabled but not AES (Microsoft Support).

Impact

The vulnerability could lead to security bypass and elevation of privilege in Windows environments. Systems using RC4-HMAC for Kerberos authentication are particularly at risk. Accounts that are flagged for explicit RC4 usage and environments that do not have AES session keys within the krbtgt account may be vulnerable to exploitation (Microsoft Support).

Mitigation and workarounds

Microsoft released security updates on November 8, 2022, to address this vulnerability. The primary mitigation involves installing these updates on all devices, including domain controllers. The update implements new registry key settings (DefaultDomainSupportedEncTypes) with a default value of 0x27, though a more secure setting of 0x3C is recommended for increased security. Organizations are advised to verify that all devices have a common Kerberos Encryption type and to move towards an AES-only environment (Microsoft Support).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management