CTD-000147

Active Directory Dangerous ACLs expose DFSR settings objects of the SYSVOL share

Critical
Active Directory
Lateral Movement Persistence Privilege Escalation
v9

Signature Identity

CTD-000147
Threat ID
9
Version
IOE
Indicator Type

Threat Description

Dangerous Access Control Lists (ACLs) in Active Directory (AD) can expose Distributed File System Replication (DFSR) settings objects. These objects are critical because they manage the replication of the SYSVOL share, which contains essential domain controller configurations, such as Group Policy Objects (GPOs). Compromising DFSR settings can lead to unauthorized changes in GPOs, which attackers can exploit for privilege escalation or persistence in the environment.

Ensuring proper ACL configurations and regularly auditing these settings can help mitigate this risk.

MITRE ATT&CK: Attack Tactics

Lateral Movement Persistence Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

  1. Open the ADSI Edit tool.
  2. Connect to the Default naming context > System.
  3. Select DFSR-GlobalSettings.
  4. Right-click to select Properties.
  5. Select the Security tab.
  6. Remove unexpected permissions.

Frequently Asked Questions

What does Active Directory Dangerous ACLs expose DFSR settings objects of the SYSVOL share mean?

Active Directory Dangerous ACLs expose DFSR settings objects of the SYSVOL share means that misconfigured Access Control Lists (ACLs) in the Active Directory environment domain grant unauthorized access to Distributed File System Replication (DFSR) settings objects, which manage SYSVOL share replication.

This vulnerability is rated critical because an attacker can exploit misconfigured DFSR settings to modify Group Policy Objects (GPOs), potentially leading to privilege escalation or persistence through unauthorized changes.

An attacker can exploit misconfigured ACLs to modify DFSR settings, granting access to critical domain controller configurations and enabling privilege escalation or persistence through unauthorized changes to Group Policy Objects (GPOs).

Cayosoft Guardian continuously monitors ACL configurations in the Active Directory environment domain, identifying misconfigured permissions that grant unauthorized access to DFSR settings objects and alerting administrators to potential security risks.

Cayosoft Guardian provides visibility into DFSR settings configurations, alerts administrators to misconfigured ACLs, and supports investigation and response efforts to ensure proper ACL configurations and mitigate unauthorized access to critical domain controller configurations.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Forest-wide Infrastructure
Attack Tactics
Lateral Movement Persistence Privilege Escalation
Defend Tactics
Domain Account Monitoring
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical