Exchange-related AD group with excessive permissions

Active Directory

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.

Dangerous ACLs expose DPAPI key objects

Active Directory

Critical exposure of DPAPI key objects in Active Directory due to misconfigured ACLs allows attackers to decrypt sensitive data through unauthorized access.

Dangerous ACLs expose Certificate Templates container

Active Directory

Critical: Non-default principals with elevated permissions on the Certificate Templates container can introduce a malicious CA, escalating privileges and compromising the domain through attack paths that exploit administrative scope and credentials.