KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This vulnerability has a 0.48% probability of being exploited in the next 30 days, ranking higher than 40% of all scored CVEs.