Junglewise Threat Intelligence

CVE-2025-11561: Red Hat SSSD Kerberos auth bypass in Active Directory integration

CVE-2025-11561 · Severity: high · CVSS 8.8 · Published 2025-10-09

Vendors: Red Hat.

Executive brief

SSSD (System Security Services Daemon) is a critical authentication service used on Linux systems to integrate with enterprise Active Directory domains. A flaw in the Kerberos authentication plugin allows attackers who can modify certain Active Directory attributes to impersonate privileged users and gain unauthorized access to domain-joined Linux hosts, potentially leading to privilege escalation and full system compromise.

Technical details

The vulnerability exists in the interaction between SSSD's Kerberos local authentication plugin (sssd_krb5_localauth_plugin) and the Active Directory integration. In default configurations, a fallback mechanism to the an2ln (account-to-login-name) plugin is possible, which can be exploited when an attacker with permission to modify AD attributes (such as userPrincipalName or samAccountName) causes an impersonation of privileged accounts. The attack vector requires the attacker to have write access to modify specific Active Directory attributes on domain-joined systems. This bypass circumvents the intended Kerberos authentication flow and allows unauthorized privilege escalation. A patch should be available from Red Hat for affected SSSD versions.

Affected products

  • Red Hat SSSD versions with default Kerberos local authentication plugin enabled

Timeline

  • 2025-10-09: disclosed
  • 2025-10-09: advisory

References