MIT Kerberos 5 (krb5) does not properly reject RC4 key-derivation checksums. The issue is triggered when a remote, authenticated attacker forges an 'AD-SIGNEDPATH' or 'AD-KDC-ISSUED' signature through vulnerabilities in certain certain one-byte stream-cipher operations. This may allow an attacker to gain elevated privileges.
Currently, there are no known workarounds or upgrades to correct this issue. However, MIT has released a patch to address this vulnerability. Check the vendor advisory or solution in the references section.