A new vulnerability in Microsoft Defender for Identity (CVE-2025-26685) enables attackers to obtain Net-NTLM hashes of critical accounts, risking Active Directory compromise. Microsoft has addressed this flaw in May 2025 patches, emphasizing the importance of proper sensor migration and account management. #MicrosoftDefender #ActiveDirectoryVulnerability
Keypoints
- The vulnerability exploits MDIโs Lateral Movement Paths (LMPs) feature through SAM-R protocol queries.
- Attackers can trigger SMB null sessions to force MDI sensors to authenticate via NTLM, exposing hashes.
- Tools like Impacket and Certipy are used in multi-stage Hash capture and relaying attacks.
- The flaw enables privilege escalation, lateral movement, and potential domain-wide control.
- Organizations should monitor anomalous authentications and consider migrating to XDR sensors and gMSAs.
Read More: https://gbhackers.com/microsoft-defender-spoofing/