H3-2025-0024
Active Directory Misconfiguration: Low-Privilege User with GenericAll Privileges
Category | SECURITY_MISCONFIGURATION |
Base Score | 8.5 |
Description
A low-privilege user has been granted GenericAll
permissions to an Active Directory object. This misconfiguration grants the user complete control over the object, including the ability to modify its membership, reset passwords, and potentially even write shadow credentials to the msDS-KeyCredentialLink
attribute. This can be exploited by attackers to escalate privileges and gain control of sensitive resources.
Impact
An attacker who exploits this misconfiguration can gain complete control over the affected Active Directory object, potentially leading to full domain compromise.