Share via

Event ID 37 - Kerberos-Key-Distribution-Center

Computer Gladiator 111 Reputation points
2021-12-06T18:25:34.75+00:00

Hello,
the events 35 and 37 started to appear in the event logs a couple of weeks ago and from what I researched, Microsoft should be providing a Windows Update for this issue. Can anyone confirm or have further insight on this issue?

Event Id 37
The Key Distribution Center (KDC) encountered a ticket that did not contain information about the account that requested the ticket while processing a request for another ticket. This prevented security checks from running and could open security vulnerabilities. See https://go.microsoft.com/fwlink/?linkid=2173051 to learn more.

Ticket PAC constructed by: <domain controller>
Client: <domain>\<computername>
Ticket for: krbtgt

Event ID 35
The Key Distribution Center (KDC) encountered a ticket-granting-ticket (TGT) from another KDC (<domain controller>) that did not contain a PAC attributes field. See https://go.microsoft.com/fwlink/?linkid=2173051 to learn more.

Thank you

Windows for business | Windows Server | User experience | Other

12 answers

Sort by: Most helpful
  1. Philipp 6 Reputation points
    2022-02-15T07:39:01.687+00:00

    In case you didn't find it already there is an update in the known issues section of the KB: https://support.microsoft.com/en-us/topic/kb5008380-authentication-updates-cve-2021-42287-9dafac11-e0d0-4cb8-959a-143bd0201041

    1 person found this answer helpful.
    0 comments No comments

  2. Anonymous
    2021-12-06T20:08:10.337+00:00

    Once all the members have been patched fully with latest cumulative update the event log warnings should go away.

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    1 person found this answer helpful.

  3. Computer Gladiator 111 Reputation points
    2021-12-09T00:30:42.26+00:00

    Here is a sample of Event ID 37 I am talking about.

    The Key Distribution Center (KDC) encountered a ticket that did not contain information about the account that requested the ticket while processing a request for another ticket. This prevented security checks from running and could open security vulnerabilities. See https://go.microsoft.com/fwlink/?linkid=2173051 to learn more.

    Ticket PAC constructed by: <domaincontroller>
    Client: domain.local\<username>
    Ticket for: krbtgt

    Thanks


  4. Anonymous
    2021-12-08T19:26:45.853+00:00

    They all stopped for me about two weeks ago.

    One log indicates a users username

    can you post it?

    0 comments No comments

  5. Computer Gladiator 111 Reputation points
    2021-12-08T17:44:46.99+00:00

    Hi, thank you for this confirmation. I manually ran updates on couple of systems but still appears to show up in the domain controller event logs. One log indicates a users username and not the system computer. Do you have an explanation for this?
    Thank you

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.