Skip to content

H3-2025-0067

LAPS Password Exposure

Category SECURITY_MISCONFIGURATION
Base Score 7.1

Description

A regular domain account was found to have access in Active Directory to the Local Administrator Password Solution (LAPS) passwords of managed hosts.

Impact

An attacker can use the exposed LAPS passwords to access managed hosts as a local administrator. This could enable an attacker to move laterally or escalate privileges in the environment.

References