Microsoft AD DS Vulnerability CVE-2026-25177 Allows Privilege Escalation

Microsoft AD DS Vulnerability CVE-2026-25177 Allows Privilege Escalation

First seen 11 Mar 2026, 11:57 UTC GbhackersCybersecuritynewsCyberpressEsecurityplanet 83% similarity 74.0

Article Content

Browse articles
ThreatCluster

On March 10, 2026, Microsoft released a critical security update addressing a high-severity vulnerability in Active Directory Domain Services (AD DS), tracked as CVE-2026-25177. This flaw, with a CVSS score of 8.8, enables authorized network attackers to escalate their privileges to full SYSTEM control. The vulnerability arises from improper restrictions on file access, potentially impacting organizations that rely on AD DS for identity and access management. As of the publication of this information, the vulnerability is considered serious due to its potential for exploitation in enterprise environments. Users are urged to apply the security update immediately to mitigate risks. The flaw affects various versions of Microsoft Windows Server that utilize AD DS. No active exploitation has been reported yet, but the severity of the vulnerability warrants prompt action. Organizations should prioritize patching to prevent potential attacks.

Key Points: • CVE-2026-25177 allows privilege escalation to SYSTEM control in AD DS. • Microsoft released a patch on March 10, 2026, with a CVSS score of 8.8. • Immediate patching is recommended to mitigate the risk of exploitation.

ThreatCluster AI

Timeline

2026-03-10
CVE-2026-25177 published and patch released
2026-03-11
Articles published reporting on the vulnerability

Community

Browse all →