← back
CVE-2026-25177

Active Directory Domain Services Elevation of Privilege Vulnerability

CVSS 8.8 HIGHEPSS 1.2%CWE-641
In short

Active Directory Domain Services allows authorized users to improperly use file and resource names to gain higher privileges on the network. This is dangerous because it lets someone who already has some access take over administrator-level control.

Technical detail

An authenticated attacker can exploit improper validation of resource names in Active Directory Domain Services to escalate privileges across the domain. The vulnerability requires prior network access and valid credentials, but allows elevation from standard user to administrative rights through crafted resource naming.

Summary generated and translated by AI from the official description.
Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →