CTD-000196

Insecure ACLs on Service Connection Points in Active Directory

High
Active Directory
Persistence Privilege Escalation
v18

Signature Identity

CTD-000196
Threat ID
18
Version
IOE
Indicator Type

Threat Description

In Active Directory, Service Connection Points (SCPs) are special objects that help domain-joined devices discover services such as Configuration Manager, Exchange Autodiscover, and custom applications. These SCPs are stored in the System container and can include connection details such as server names, ports, and protocols. To function correctly, clients must be able to trust the information stored in these SCPs.

A common security oversight is applying overly permissive Access Control Lists (ACLs) to these objects, allowing broad groups such as Authenticated Users or Domain Users to modify them. This is risky because attackers who gain access to a standard user account can exploit these permissions to change SCP values—especially attributes such as serviceBindingInformation. By doing so, they can redirect domain-joined clients to attacker-controlled systems that clients may trust implicitly. As a result, clients may unknowingly send credentials, sensitive data, or service traffic to rogue endpoints, enabling man-in-the-middle (MitM) attacks, credential theft, and lateral movement across the environment.

MITRE ATT&CK: Attack Tactics

Persistence Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

  1. Open ADSI Edit.
  2. Select View > Advanced Features.
  3. Navigate to Default naming context > Domain Controllers (or Computers), depending on where the SCP is located.
  4. Locate the Service Connection Point (SCP) object with overly permissive permissions.
  5. Right-click the object and select Properties.
  6. Open the Security tab.
  7. Review the listed principals and remove or restrict any unnecessary users or groups (for example, broad groups like Authenticated Users or Domain Users).
  8. Click OK to save your changes.

Frequently Asked Questions

What does Insecure ACLs on Service Connection Points in Active Directory mean?

Insecure ACLs on Service Connection Points in Active Directory refer to overly permissive Access Control Lists (ACLs) applied to Service Connection Point objects, allowing broad groups such as Authenticated Users or Domain Users to modify them.

Insecure ACLs on Service Connection Points in Active Directory are rated high severity because they allow attackers to modify serviceBindingInformation attributes, enabling man-in-the-middle attacks and credential theft through Kerberos authentication exploitation.

Attackers gain access to a standard user account and exploit the overly permissive permissions on SCP objects to change serviceBindingInformation attributes, redirecting clients to attacker-controlled systems. This enables man-in-the-middle attacks and credential theft through Kerberos authentication exploitation.

Cayosoft Guardian continuously monitors the state of SCP objects across the Active Directory environment domain, detecting overly permissive permissions and flagging them as security issues for administrators to review and correct.

Cayosoft Guardian alerts administrators to review and correct SCP object permissions, ensuring only necessary users or groups have access to modify SCP attributes and preventing attackers from exploiting these permissions.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure Privileged Access Management
Attack Tactics
Persistence Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical