CVE-2022-33679 is an elevation of privilege vulnerability in the Windows Kerberos authentication protocol. The vulnerability allows an attacker to gain elevated privileges by exploiting flaws in the way Kerberos tickets are validated or processed, potentially bypassing security controls and gaining unauthorized access to resources.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Python script (CVE-2022-33679.py) that implements a proof-of-concept exploit for CVE-2022-33679, a vulnerability in Microsoft's Kerberos implementation. The script leverages the Impacket library to construct and send Kerberos AS_REQ packets to a Key Distribution Center (KDC), typically a Windows domain controller. It manipulates the cryptographic fields in the Kerberos response and attempts to brute-force part of the keystream to recover the session key, demonstrating the vulnerability. The script is self-contained, with the main entry point at the bottom, and is designed for research and demonstration purposes. The only network endpoint involved is the KDC, which is contacted over TCP port 88. No hardcoded IPs or domains are present; the user must supply the target domain and username. The exploit does not provide a weaponized payload but demonstrates the cryptographic weakness, making it a POC.
This repository contains a single Python exploit script (CVE-2022-33679.py) targeting the Microsoft Windows Active Directory Kerberos implementation, specifically accounts with the 'Do not require Kerberos preauthentication' flag set. The exploit leverages the vulnerability described in CVE-2022-33679, allowing an attacker to request a Ticket Granting Ticket (TGT) for such accounts without knowing the password, and then request a Ticket Granting Service (TGS) ticket for a specified service. The script uses the impacket and arc4 libraries to craft and send Kerberos protocol messages directly to a domain controller (whose IP can be specified via the -dc-ip argument). The resulting Kerberos ticket is saved as a .ccache file for later use. The repository also includes a README with usage instructions, a requirements.txt listing dependencies, and a LICENSE file. The exploit is a proof-of-concept and does not include weaponized payloads, but demonstrates the vulnerability's impact by obtaining valid Kerberos tickets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.