Microsoft Patches Critical Active Directory Flaws Amid Ransomware Concerns
Microsoft has patched two critical vulnerabilities in its Active Directory service, dubbed ResetNightmare and KerberLoss. These flaws allow attackers to manipulate how the directory distinguishes between legitimate users, service accounts, and privileged identities.
The issues were discovered by researchers at Semperis, who found that they could be exploited using hidden Unicode characters and weaknesses in Active Directory name validation.
According to Semperis, the flaws could let an attacker make two different accounts or services appear to share the same name, which could disrupt access to business systems or allow an attacker to impersonate a privileged user.
The researchers said that ResetNightmare is the more serious issue because it could let a low-privileged attacker take control of an entire Active Directory domain under certain conditions. KerberLoss offers a separate route to abuse weaknesses in identity handling within the directory service.