CVE-2025-29810

Published Apr 8, 2025

Last updated 3 months ago

Overview

Description
Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
Source
secure@microsoft.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
5.9
Exploitability score
1.6
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-284

Social media

Hype score
Not currently trending
  1. Microsoft has disclosed a critical security vulnerability in Active Directory Domain Services, tracked as CVE-2025-29810, which could allow attackers to escalate privileges to the SYSTEM level. More: https://t.co/uur713y52Q #Hoploninfosec #CyberSecurity #MicrosoftSecurity https:

    @HoplonInfosec

    11 Apr 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ๐Ÿ‘‰๐–๐ข๐ง๐๐จ๐ฐ๐ฌ ๐€๐œ๐ญ๐ข๐ฏ๐ž ๐ƒ๐ข๐ซ๐ž๐œ๐ญ๐จ๐ซ๐ฒ ๐ƒ๐จ๐ฆ๐š๐ข๐ง ๐•๐ฎ๐ฅ๐ง๐ž๐ซ๐š๐›๐ข๐ฅ๐ข๐ญ๐ฒ ๐‹๐ž๐ญ ๐€๐ญ๐ญ๐š๐œ๐ค๐ž๐ซ๐ฌ ๐„๐ฌ๐œ๐š๐ฅ๐š๐ญ๐ž ๐๐ซ๐ข๐ฏ๐ข๐ฅ๐ž๐ ๐ž๐ฌ (CVE-2025-29810) #PatchTuesday #SecurityUpdateGuide #Microsoft #informationsecurity #security #CVE #Vulnerability https:/

    @BhanuNaik_2026

    10 Apr 2025

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. There is a new vulnerability with elevated criticality in Microsoft Windows (CVE-2025-29810) https://t.co/h3jNKEjum2

    @vuldb

    9 Apr 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-29810: Critical Active Directory Flaw and Mitigation Strategies https://t.co/KchlJQWPoJ

    @windowsforum

    9 Apr 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-29810 Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. https://t.co/w5En78cQK1

    @CVEnew

    8 Apr 2025

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.