CyberRota Analysis
AI-GeneratedDeployments utilizing BoKS keytab management are vulnerable due to the generation of Active Directory service-account passwords from a predictable pseudo-random sequence based on the current Unix timestamp. This flaw allows attackers with knowledge of the service principal and an estimated password-change time to reproduce potential passwords and verify them offline, leading to unauthorized access. Organizations using affected versions should prioritize remediation to mitigate the risk of credential compromise.
Original NVD Description
In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.