Executive brief
Windows Active Directory, a core directory service that manages user identities and access control across enterprise networks, contains a weakness in its encryption implementation. An authorized attacker on the network could exploit this flaw to bypass a security feature, potentially compromising access controls or exposing sensitive authentication data.
Technical details
This vulnerability stems from inadequate encryption strength in Windows Active Directory's security mechanisms. An authorized attacker with network access can bypass a security feature by exploiting weak encryption parameters. The attack requires prior authorization to the system and network reachability. Successful exploitation could lead to circumvention of intended security controls. A patch is available from Microsoft.
Affected products
- Microsoft Windows Active Directory <UNKNOWN>
Timeline
- 2026-08-11: disclosed