CVE-2026-25177

CWE-6415 documents5 sources
Severity
8.8HIGH
EPSS
0.1%
top 73.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10

Description

Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages29 packages

NVDmicrosoft/windows< 10.0.14393.8957+5
NVDmicrosoft/windows_10_1607< 10.0.14393.8957
NVDmicrosoft/windows_10_1809< 10.0.17763.8511
NVDmicrosoft/windows_10_21h2< 10.0.19044.7058
NVDmicrosoft/windows_10_22h2< 10.0.19045.7058

🔴Vulnerability Details

2
GHSA
GHSA-f3vf-8qf4-r2f7: Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges ov2026-03-10
CVEList
Active Directory Domain Services Elevation of Privilege Vulnerability2026-03-10

📋Vendor Advisories

1
Microsoft
Active Directory Domain Services Elevation of Privilege Vulnerability2026-03-10

🕵️Threat Intelligence

1
Wiz
CVE-2026-25177 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-25177 (HIGH CVSS 8.8) | Improper restriction of names for f | cvebase.io