Microsoft Defender Spoofing Flaw Enables Privilege Escalation and AD Access

Microsoft Defender Spoofing Flaw Enables Privilege Escalation and AD Access

A new vulnerability in Microsoft Defender for Identity (CVE-2025-26685) enables attackers to obtain Net-NTLM hashes of critical accounts, risking Active Directory compromise. Microsoft has addressed this flaw in May 2025 patches, emphasizing the importance of proper sensor migration and account management. #MicrosoftDefender #ActiveDirectoryVulnerability

Keypoints

  • The vulnerability exploits MDIโ€™s Lateral Movement Paths (LMPs) feature through SAM-R protocol queries.
  • Attackers can trigger SMB null sessions to force MDI sensors to authenticate via NTLM, exposing hashes.
  • Tools like Impacket and Certipy are used in multi-stage Hash capture and relaying attacks.
  • The flaw enables privilege escalation, lateral movement, and potential domain-wide control.
  • Organizations should monitor anomalous authentications and consider migrating to XDR sensors and gMSAs.

Read More: https://gbhackers.com/microsoft-defender-spoofing/