📎 AI Summary:
The thread discusses a reported "Kerberos Information Disclosure" vulnerability on Windows Server 2012 R2, with the original poster seeking guidance on restricting access to the Kerberos service. A responder clarifies that it is an informational alert with minimal security risk, especially on domain-joined systems, and questions whether recent patches address the issue. Overall, the consensus suggests that the vulnerability is low risk and may not require immediate action.

kalyani

New Member
Member details
Joined
Sep 20, 2019
Messages
2
Thread Author #1
Vulnerability is detected on "Kerberos Information Disclosure" . According to vulnerability scanning tool below vulnerability is detected on windows 2012 R2. We have to fix it.

Explanation of Issue:
The remote Kerberos service discloses an accurate timestamp as well as the name of its authentication domain. This
information could prove useful to an attacker looking to attack the kerberos authentication system or other devices
which use it.

Recommendation:
Access to the Kerberos service should be restricted to devices that require it.

According to the above recommendation we have to restrict the kerberos service to the devices.
Please share us the settings/configuration to restrict access to kerberos for a particular device/system
 

Neemobeer

Windows Forum Team
Staff member
Member details
Joined
Jul 4, 2015
Messages
8,995
This is an info level "vulnerability" there is little to no risk associated to it.l If an attacker was on domain joined system they should be able to legitimately get this information anyways.
 

kalyani

New Member
Member details
Joined
Sep 20, 2019
Messages
2
Thread Author #3
Thanks for the reply,
Any latest Microsoft patches are solving this issue ?
 

Neemobeer

Windows Forum Team
Staff member
Member details
Joined
Jul 4, 2015
Messages
8,995
No an info vulnerability isn't really a vulnerability.