Microsoft has patched a critical Active Directory Domain Services (AD DS) vulnerability (CVE‑2026‑25177)

 


Microsoft has patched a critical Active Directory Domain Services (AD DS) vulnerability (CVE‑2026‑25177) that allows attackers with minimal privileges to escalate to full SYSTEM access. The flaw, rated 8.8 CVSS, affects Windows Server environments and was fixed in the March 2026 Patch Tuesday update.

How the Exploit Works

  • Unicode manipulation: Attackers use hidden Unicode characters to create duplicate SPNs or UPNs.
  • Kerberos confusion: When a client requests a Kerberos ticket for a duplicate SPN, the domain controller issues a ticket encrypted with the wrong key.
  • Fallback risk: This can trigger NTLM fallback (if enabled) or cause denial-of-service.
  • Privilege escalation: With SPN write access, attackers can escalate to SYSTEM without touching the target server directly.

Affected Systems

  • Windows Server 2012 → Server 2025
  • Windows 10 and 11 (if acting as domain controllers)
  • Any AD DS deployment with Kerberos and NTLM enabled

Security Implications

  • Domain-wide compromise: SYSTEM access allows full control over authentication, GPOs, and sensitive data.
  • Credential theft: Attackers can harvest secrets, disable security controls, and install persistent malware.
  • Kerberos disruption: Authentication failures and fallback to NTLM increase exposure to relay attacks.

Recommended Actions for Admins

  1. Apply March 2026 security updates immediately
    • Covers all supported Windows Server and client OS versions.
  2. Audit SPN/UPN changes
    • Look for unusual or duplicate entries with hidden characters.
  3. Disable NTLM fallback if possible
    • Reduces risk of downgrade attacks.
  4. Monitor Kerberos ticketing anomalies
    • Failed authentications or unexpected fallback behavior.
  5. Use Semperis or similar AD monitoring tools
  • Microsoft coordinated with Semperis to detect and mitigate this flaw.






Popular posts from this blog

WSUS CVE-2025-59287 Mitigation

Cloud Infrastructures are Having a Bad Week

CVE-2025-58034 Fortinet Warnings and Mitigation