Executive brief
SSSD (System Security Services Daemon) is a critical authentication service used on Linux systems to integrate with enterprise Active Directory domains. A flaw in the Kerberos authentication plugin allows attackers who can modify certain Active Directory attributes to impersonate privileged users and gain unauthorized access to domain-joined Linux hosts, potentially leading to privilege escalation and full system compromise.
Technical details
The vulnerability exists in the interaction between SSSD's Kerberos local authentication plugin (sssd_krb5_localauth_plugin) and the Active Directory integration. In default configurations, a fallback mechanism to the an2ln (account-to-login-name) plugin is possible, which can be exploited when an attacker with permission to modify AD attributes (such as userPrincipalName or samAccountName) causes an impersonation of privileged accounts. The attack vector requires the attacker to have write access to modify specific Active Directory attributes on domain-joined systems. This bypass circumvents the intended Kerberos authentication flow and allows unauthorized privilege escalation. A patch should be available from Red Hat for affected SSSD versions.
Affected products
- Red Hat SSSD versions with default Kerberos local authentication plugin enabled
Timeline
- 2025-10-09: disclosed
- 2025-10-09: advisory