In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
Exploitation requires knowledge of the affected service principal, an estimate of the password-change time, and suitable Kerberos ticket material. A standard authenticated Active Directory account can ordinarily request a service ticket for an SPN assigned to the affected account; administrative access to BoKS, the service host, or its keytab is not normally required. A previously captured service ticket can alternatively provide offline verification material.
Installing the update does not secure passwords generated by an affected release. Rotate all affected or uncertain service-account passwords through BoKS keytab management and confirm distribution of the new key version. After the Active Directory domain's configured maximum service-ticket lifetime plus clock-skew allowance has elapsed, rebuild affected keytabs during a maintenance window so they retain only the current key version. Redistribute and verify the keytabs, restart or reload dependent services as required, and test Kerberos authentication. If compromise is suspected, rotate and rebuild immediately rather than waiting for existing tickets to expire.
Upgrade the active BoKS Master to boks-server 9.0.0.7 and restart BoKS before generating replacement passwords.