Critical Active Directory Flaws Patched By Microsoft Amid Ransomware Concerns
Microsoft has patched two critical Active Directory vulnerabilities that could allow attackers to escalate privileges and interfere with authentication. The flaws, known as ResetNightmare and KerberLoss, affect how Microsoft Active Directory interprets usernames and service names.
The vulnerabilities were discovered by Semperis researchers and were classified as Important Elevation of Privilege vulnerabilities in Microsoft's severity system. Both issues have been patched, with KerberLoss addressed in March and ResetNightmare in April.
The flaws could let an attacker make two different accounts or services appear to share the same name, disrupting access to business systems or allowing an attacker to impersonate a privileged user. In some cases, it may even be possible for a low-privileged attacker to take control of an entire Active Directory domain.
Active Directory remains central to many corporate networks, managing user identities, access rights, and relationships between systems. The platform is still used in roughly 90% of enterprise environments, making any weakness significant for large organisations.