CVE-2026-25177Disclosure(microsoft / windows_10_1607)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

2.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-641

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 18 mentions across 14 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 15 signals
  • Disclosure: 10 classified signals
  • Peaked 11d ago at 3 mentions (2026-03-13); latest day: 1
  • 18 total mentions across 14 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline18 mentions / 14d
01223Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-13: 3Mentions · 2026-03-16: 2Mentions · 2026-03-17: 1Mentions · 2026-03-19: 2Mentions · 2026-04-10: 1Mentions · 2026-06-16: 1Mentions · 2026-06-17: 1Mentions · 2026-06-18: 1Mentions · 2026-08-09: 1Mentions · 2026-08-10: 1Mentions · 2026-08-17: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-08-10: 1PoC Mentioned / Linked · 2026-09-11: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-13: 2Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-08-17: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-13: 2Technical Details · 2026-03-16: 2Technical Details · 2026-03-17: 1Technical Details · 2026-03-19: 2Technical Details · 2026-04-10: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-18: 1Technical Details · 2026-08-09: 1Technical Details · 2026-08-10: 1Technical Details · 2026-08-17: 103-1003-1103-1303-1603-1703-1904-1006-1606-1706-1808-0908-1008-1709-11
Signal classification3 categories
Disclosure
1055.6%
Patch
633.3%
PoC
211.1%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-111
Patch1
2026-03-133
Disclosure1Patch2
2026-03-162
Disclosure2
2026-03-171
Disclosure1
2026-03-192
Disclosure2
2026-04-101
Patch1
2026-06-161
Disclosure1
2026-06-171
Patch1
2026-06-181
Disclosure1
2026-08-091
Disclosure1
2026-08-101
PoC1
2026-08-171
Patch1
2026-09-111
PoC1
Full discourse18 posts
  • Swissky@pentest_swissky
    PoC

    Exploiting AD ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177) from Linux - @rouge_cravate https://cravaterouge.com/articles/resetnightmare/

    Post summary

    The author announces exploitation of two Linux CVEs and links to a resource that likely contains PoC details.

    045019416212.8K
    23.2K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    ⚠️ A patched AD bug may not end the risk. Richard Lambert of One Identity explains how CVE-2026-25177 exposes a deeper problem: overbroad AD rights, service account sprawl, and weak governance. Patch fast. Then fix the permissions underneath. Read the article: https://thehackernews.com/expert-insights/2026/06/why-active-directory-vulnerabilities.html

    Post summary

    The article stresses that applying the CVE‑2026‑25177 patch is essential but not enough; users must also audit and tighten Active Directory permission structures.

    01014079.5K
    2.2M followersView on X
  • @Cravaterouge.infosec.exchange@rouge_cravate
    PoC

    Exploit demo on Linux and Patch Analysis of ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177), two Active Directory vulnerabilities discovered by Shai Laron from @SemperisTech allowing Full Domain Takeover and more. https://cravaterouge.com/articles/resetnightmare/

    Post summary

    The post notes a Linux-based exploitation demo for two Active Directory CVEs and a patch analysis, confirming that a PoC was demonstrated but providing no specific exploit code or active attack evidence.

    060841.3K
    330 followersView on X
  • 0patch@0patch
    Patch

    Micropatches released for "KerberLoss" Active Directory Domain Services Elevation of Privilege Vulnerability (CVE-2026-25177) https://0patch.com/blog/micropatches-released-for-kerberloss-active-directory-domain-services-elevation-o https://t.co/lgjPUmKUAX

    Post summary

    The announcement informs that micropatches have been released for the CVE-2026-25177 Elevation of Privilege flaw in Active Directory Domain Services, focusing on remediation.

    15081701
    8.4K followersView on X
  • Harrison McCall@LeadHead0
    Disclosure

    Weakness #2: Lateral Movement via "Naming Edge Cases" (CVE-2026-25177)The latest 2026 exploits involve improper restriction of resource names. Attackers use Unicode normalization and "Ghost SPNs" to trick the Kerberos KDC into issuing tickets for accounts they shouldn't access. It’s silent and deadly.

    Post summary

    The passage announces a new Windows Kerberos elevation vulnerability (CVE-2026-25177) that enables lateral movement via Unicode normalization and Ghost SPNs, though it provides no PoC, exploit code, patch, or proof of active exploitation.

    1000054
    51 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Microsoft AD DS の脆弱性 CVE-2026-25177 が FIX:Unicode SPN 偽装による SYSTEM 権限奪取 https://iototsecnews.jp/2026/03/11/microsoft-active-directory-domain-services-vulnerability-let-attackers-escalate-privileges/ この脆弱性 CVE-2026-25177 の原因は、本来なら重複が許されない識別子である SPN や UPN が、特殊な Unicode 文字により偽装できてしまうところにあります。Active Directory のセキュリティ・チェックにおいて、これらの不可視文字が適切に処理されず、システムが “別物” として誤認してしまう隙を突かれる可能性があります。 その結果として、認証の仕組みである Kerberos 認証が正常に機能しなくなり、意図しないサービス停止や、より安全性の低い認証方式への誘導を招く恐れがあります。ID 管理の根幹に関わる問題であり、文字の処理という基本的な制限の不備が、ドメイン全体の制御権という大きなリスクに繋がってしまいます。ご利用のチームは、ご注意ください。 #ActiveDirectoryDomainServices #CVE202625177 #Microsoft #Vulnerability

    Post summary

    The article announces the discovery of CVE-2026-25177 in Microsoft AD DS, detailing how Unicode‑based SPN spoofing can cause privilege escalation, but it does not provide PoC code, active exploitation reports, or a specific patch.

    01000183
    484 followersView on X
  • Ronin66@Ronin66Official
    Disclosure

    KerberLoss (CVE-2026-25177) + ResetNightmare (CVE-2026-27912): two Kerberos logic flaws. Low-priv user → any account → domain admin → full domain takeover. Presented today at Black Hat USA by Semperis. https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/ #infosec #ActiveDirectory

    Post summary

    Semperis disclosed two Kerberos logic flaw CVEs (CVE‑2026‑25177 and CVE‑2026‑27912) at Black Hat USA, outlining a low‑privilege user path to full domain takeover, with no PoC, exploit, or patch details provided.

    0000081
    27 followersView on X
  • SPIN IDG@spinidg
    Disclosure

    Experts call for stronger Active Directory governance after CVE-2026-25177 disclosure raises concerns over privilege escalation and identity security risks. Read More: https://csopakistan.com/experts-urge-stronger-active-directory-governance-following-disclosure-of-cve-2026-25177/ @Microsoft @OneIdentity @msftsecurity

    Post summary

    The article reports the CVE-2026-25177 disclosure, highlighting privilege escalation risks, and urges stronger Active Directory governance.

    0000032
    2.0K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    CVE-2026-25177 shows why Active Directory flaws need more than patching: SPN manipulation and Kerberos abuse can raise privileges, so least-privilege governance and tight service account control are essential. #ActiveDirectory #Kerberos #PrivEsc https://ift.tt/BlvKMpb

    Post summary

    CVE-2026-25177 exploits SPN manipulation and Kerberos abuse to raise privileges in Active Directory, underscoring that patching alone is not enough to mitigate the risk.

    00000113
    4.4K followersView on X
  • Alexei Belous@AlexeiBelous
    Patch

    AD security lesson: “identity” = directory integrity. CVE-2026-25177 is described as a naming restriction bug in AD DS, but low-priv + network reachable + no UI = any domain user foothold can become domain control. Patch - and watch for weird AD object names/changes.

    Post summary

    The post describes a naming restriction vulnerability in AD that allows domain elevation without UI and notes that a patch is available, advising users to monitor AD object names.

    0000031
    7 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-25177 | Active Directory Domain Services Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-25177 https://t.co/1jQUyUCug5

    Post summary

    A new CVE, CVE-2026-25177, is announced as an Active Directory Domain Services elevation‑of‑privilege vulnerability, with only a reference link provided.

    0000040
    2 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25177 Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-25177 ----- Traducción: CVE-2026-25177 Restricc… http://infoflow.cloud`

    Post summary

    The post discloses CVE-2026-25177, detailing a privilege‑elevation vulnerability in Active Directory Domain Services.

    0000047
    58 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25177 Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-25177

    Post summary

    The post announces CVE‑2026‑25177 with a concise description and a link to the CVE record, but does not mention PoC, exploits, or mitigations.

    00000301
    56.7K followersView on X
  • AllCy@all_cy43793
    Disclosure

    🚨ALERTA RÁPIDA  🔐 CVE-2026-25177 — Microsoft Active Directory Domain Services #Microsoft #ActiveDirectory #AD #vulnerability #cybersecurity #AllCy https://www.linkedin.com/posts/allcy_alerta-r%C3%A1pida-cve-2026-25177-microsoft-activity-7438299525494157312-mja-

    Post summary

    The post is a brief alert announcing CVE‑2026‑25177 in Microsoft Active Directory Domain Services, with no exploitation, patch, or technical detail provided.

    0000044
    1 followersView on X
  • renato (sheepmaster) rossetti@sheepmaster74
    Patch

    CVE-2026-25177 - Security Update Guide - Microsoft - Active Directory Domain Services Elevation of Privilege Vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25177

    Post summary

    The text references Microsoft’s Security Update Guide for CVE‑2026‑25177, indicating an available patch for an AD DS elevation‑of‑privilege vulnerability while providing minimal technical detail.

    0000039
    190 followersView on X
  • TechPio@techpio_team
    Patch

    🚨 AD Security Alert A new flaw (CVE-2026-25177) in Microsoft Active Directory could allow attackers to gain full SYSTEM privileges. Patch your servers ASAP to stay protected. 🔗 https://cybersecuritynews.com/active-directory-domain-services-vulnerability-2/ #CyberSecurity #ActiveDirectory #PatchTuesday #InfoSec #MicrosoftSecurity https://t.co/bW5WpNPYZx

    Post summary

    The message is a patch advisory for CVE‑2026‑25177, urging administrators to update their Microsoft Active Directory servers immediately.

    0000050
    414 followersView on X
  • ✮ Cymon Skinner ✮@CymonSkinner
    Patch

    A new Active Directory Domain Services elevation-of-privilege vulnerability, CVE-2026-25177, allows attackers to escalate privileges, with a CVSS score of 8.8. This flaw targets the core of identity management in Windows environments, potentially enabling unauthorised access to sensitive resources. CISOs should prioritise checking Microsoft's March 2026 security updates and staging patches for domain controllers. Enhance monitoring to detect anomalous authentication attempts early. #CyberSecurity #ActiveDirectory

    Post summary

    The post announces a new AD elevation-of-privilege CVE (2026‑25177) with a high CVSS score and urges rapid patching via Microsoft’s March 2026 update.

    0000092
    711 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25177: HIGH] Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.#cve,CVE-2026-25177,#cybersecurity https://cvefind.com/CVE-2026-25177

    Post summary

    The post announces CVE‑2026‑25177, a privilege‑elevation flaw in Active Directory Domain Services, providing the CVE identifier and a brief description of the vulnerability.

    0000077
    601 followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025--x64

Explore more