Skip to content

H3-2025-0024

Active Directory Misconfiguration: Low-Privilege User with GenericAll Privileges

Category SECURITY_MISCONFIGURATION
Base Score 8.5

Description

A low-privilege user has been granted GenericAll permissions to an Active Directory object. This misconfiguration grants the user complete control over the object, including the ability to modify its membership, reset passwords, and potentially even write shadow credentials to the msDS-KeyCredentialLink attribute. This can be exploited by attackers to escalate privileges and gain control of sensitive resources.

Impact

An attacker who exploits this misconfiguration can gain complete control over the affected Active Directory object, potentially leading to full domain compromise.

References