CTD-000089

AD domain with unsecure RBCD delegation on domain controllers

Critical
Active Directory
Credential Access
v19

Signature Identity

CTD-000089
Threat ID
19
Version
IOC-IOE
Indicator Type

Threat Description

A threat actor could exploit this vulnerability by identifying non-privileged users outside of the Domain Admins, Enterprise Admins, or Built-in Admins groups who possess write access to Resource-Based Constrained Delegation (RBCD) settings on domain controllers. With write access, attackers can enable a resource to impersonate any user, except those explicitly restricted by delegation settings.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To change permissions using Active Directory Users and Computers:

  1. Press View > Advanced features.
  2. Locate the domain controller object.
  3. Right-click on it, and select Properties.
  4. Select the Security tab.
  5. Remove unwanted users or groups.
  6. Click OK to save the permission settings.

Frequently Asked Questions

What does AD domain with unsecure RBCD delegation on domain controllers mean?

Unsecure RBCD delegation on domain controllers allows non-privileged users outside of the Domain Admins, Enterprise Admins, or Built-in Admins groups to modify Resource-Based Constrained Delegation settings. This enables attackers to create unauthorized Kerberos service tickets for any user, except those explicitly restricted by delegation settings.

This vulnerability allows attackers to bypass normal authentication and access controls, enabling them to access sensitive resources and data without proper authorization. The attacker's ability to create unauthorized Kerberos service tickets for any user makes this a critical issue.

Attackers can use the modified RBCD settings to obtain a Kerberos ticket-granting service (TGS) ticket for any user, allowing them to access sensitive resources and data without proper authentication. This enables lateral movement and escalation of privileges.

Cayosoft Guardian continuously monitors the permissions and access controls on your domain controllers, detecting non-privileged users with write access to RBCD settings and flagging this as a security issue for administrators to address.

Cayosoft Guardian alerts administrators to remove unwanted users or groups from RBCD settings, limiting the ability of attackers to create unauthorized Kerberos service tickets and reducing the risk of severe compromise. This helps provide visibility into potential attack paths and supports investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure
Attack Tactics
Credential Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical