Exchange-related AD group with excessive permissions

Active Directory

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.

Dangerous ACLs expose DPAPI key objects

Active Directory

Critical exposure of DPAPI key objects in Active Directory due to misconfigured ACLs allows attackers to decrypt sensitive data through unauthorized access.

Dangerous ACLs expose Certificate Templates container

Active Directory

Critical: Non-default principals with elevated permissions on the Certificate Templates container can introduce a malicious CA, escalating privileges and compromising the domain through attack paths that exploit administrative scope and credentials.

Inactive AD domain controller

Active Directory

Inactive AD domain controllers expose authentication and authorization risks due to potential secrets expiration, enabling attackers to exploit expired tickets for unauthorized access.