CVE-2012-1012 — Kerberos 5 vulnerability
Severity
5.5MEDIUMNVD
EPSS
0.2%
top 53.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 7
Latest updateMay 13
Description
server/server_stubs.c in the kadmin protocol implementation in MIT Kerberos 5 (aka krb5) 1.10 before 1.10.1 does not properly restrict access to (1) SET_STRING and (2) GET_STRINGS operations, which might allow remote authenticated administrators to modify or read string attributes by leveraging the global list privilege.
CVSS vector
AV:N/AC:L/C:P/I:P/A:NExploitability: 8.0 | Impact: 4.9