ThreatCluster

Multiple Vulnerabilities in MIT Kerberos 5 Identified and Published

First seen 18 Feb 2026, 13:23 UTC Api.Msrc.Microsoft 34

Article Content

Browse articles
ThreatCluster

Two vulnerabilities in MIT Kerberos 5 (krb5) before version 1.21.3 have been identified. CVE-2024-37370 allows an attacker to modify the Extra Count field of a GSS krb5 wrap token, while CVE-2024-37371 enables invalid memory reads during GSS message token handling. Both vulnerabilities were published on June 28, 2024.

Timeline

2024-06-28
CVE-2024-37370 published
2024-06-28
CVE-2024-37371 published
2026-02-18
Information published about CVE-2024-37370 and CVE-2024-37371