cognitive cybersecurity intelligence

News and Analysis

Search

Microsoft Defender Spoofing Vulnerability Let Attackers Escalate Privilege & Gain Access to AD Environment

Microsoft Defender Spoofing Vulnerability Let Attackers Escalate Privilege & Gain Access to AD Environment

A critical vulnerability in Microsoft Defender for Identity (CVE-2025-26685) allows unauthenticated attackers to escalate privileges and access Active Directory by exploiting the Lateral Movement Paths feature in MDI sensors. Attackers can capture authentication credentials via a downgraded authentication process, enabling significant reconnaissance and privilege escalation. Mitigations include migrating to unified XDR sensors and monitoring authentication events for anomalies.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts