Attacks on Active Directory - Resource-based Constrained Delegation and New Patches
Jean Rosemond Dora, Ladislav Hluchý · 2025
From our previous paper [1], we have seen the importance of constrained delegation (CD) regarding the security of active directory (AD). Additionally, we have also seen how attackers can successfully abuse this security feature. This paper represents the final work. Since the attack exploitation has been disclosed, Microsoft applied a resource-based (RBCD) technique to eliminate the requirement of highly elevated access rights from system administrators, SeEnableDelegationPrivilege for example. Moreover, since this security mechanism was introduced in 2012, attackers have found strategies to defeat it. Therefore, we need to know the cause and consequences of applying a patch and consider a higher standard security mechanism for our environment. AD is usually addressed for large-scale deployment. It is a bottom-line component that handles several authentication types. Its configuration requires a high level of understanding of every object’s role, thus making it complex to properly cover all the security measures. For example, the Object Security Permissions (OSP), and the Kerberos Delegation (KD) play a great role and thus require great attention in the configuration phase. As a result, attackers with access to a company’s AD can look after wrongly addressed security features and exploit them. This can lead to an entire compromise of that company. This paper will focus on the exploitation of AD through the resource-based constrained delegation (RBCD). The enumeration phase will also be addressed to reveal the presence of this vulnerability. Then, we will briefly address the newest techniques and patches that need to be applied, as of October 2024.