Microsoft Patches Critical Active Directory Flaws, Leaving Enterprise Networks Vulnerable
Microsoft has issued patches for two critical Active Directory vulnerabilities discovered by Semperis researchers. The flaws, known as ResetNightmare and KerberLoss, affect how Microsoft Active Directory interprets usernames and service names. This can create a path for attackers to escalate privileges and interfere with authentication.
The vulnerabilities could let an attacker make two different accounts or services appear to share the same name, disrupting access to business systems, forcing some services to fall back to weaker authentication methods, or allowing an attacker to impersonate a privileged user. ResetNightmare is considered the more serious issue because it can allow a low-privileged attacker to take control of an entire Active Directory domain under certain conditions.
Active Directory remains central to many corporate networks, managing user identities, access rights, and relationships between systems. The platform is still used in roughly 90% of enterprise environments, making any weakness significant for large organisations. Microsoft classified both issues as Important Elevation of Privilege vulnerabilities and patched them in March and April, respectively.
Researchers pointed to Active Directory auditing as a way to spot suspicious changes after patching, including using Security Event ID 5136 to identify unusual directory modifications that may indicate attempts to exploit naming confusion or alter critical settings. The disclosure highlights the challenge of securing legacy identity infrastructure that has grown over years of operational use.