PT-2026-24304 · Microsoft · Active Directory Domain Services+1

·

CVE-2026-25177

·

Published

2026-03-10

·

Updated

2026-09-11

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Active Directory Domain Services (affected versions not specified)
Description Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network, potentially gaining full SYSTEM privileges. Attackers can utilize Unicode normalization and Ghost SPNs (Service Principal Names) to deceive the Kerberos KDC (Key Distribution Center) into issuing tickets for unauthorized accounts, facilitating lateral movement.
Recommendations Apply the Microsoft March 2026 security updates to domain controllers. Review and restrict overbroad Active Directory rights and service account permissions to minimize the risk of privilege escalation.

Fix

LPE

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02896
CVE-2026-25177

Affected Products

Active Directory Domain Services
Windows