
Netwrix Security Research, led by Huy Kha, identified an ESC1 privilege escalation path in certain versions of SafeNet Agent for Windows Logon. The issue, tracked as CVE-2026-0872, stemmed from an insecure AD CS certificate template configuration that allowed any authenticated user to escalate to Domain Admin. Read the blog to learn about the CVE and the recommended mitigation 👉https://netwrix.com/en/resources/blog/how-i-got-domain-admin-via-safenet-agent-for-windows-logon-through-esc1/?cID=701Qk00000TfcKSIAZ&utm_source=smm&utm_medium=twitter&utm_campaign=product-demo #Netwrix #IdentitySecurity #DataSecurity #SecurityResearch
Post summary
The post announces CVE-2026-0872, a privilege escalation flaw in SafeNet Agent for Windows Logon, and directs readers to mitigation steps, with no PoC, active exploitation, or false‑positive claims reported.


