CVE-2026-20833
MEDIUMWindows Server 2008 and later - Information Disclosure via Broken Cryptographic Algorithm in Kerberos
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2026-20833. PoCs published by AlMarWorld, v-jfanca.
AI-analyzed exploit summary This repository provides a PowerShell-based auditing tool for Kerberos authentication events in Active Directory environments. It collects and analyzes Kerberos-related security events (IDs 4768, 4769, 4771) from domain controllers but does not exploit any vulnerability.
Description
Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.
Exploits (2)
This repository provides a PowerShell-based auditing tool for Kerberos authentication events in Active Directory environments. It collects and analyzes Kerberos-related security events (IDs 4768, 4769, 4771) from domain controllers but does not exploit any vulnerability.
This repository provides comprehensive technical documentation and operational guidance for detecting and remediating RC4 usage in Kerberos authentication, as part of Microsoft's security changes for CVE-2026-20833. It includes PowerShell scripts, Power BI dashboards, and detailed analysis of Kerberos encryption usage.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N