AI description
CVE-2026-27912 is an improper authorization vulnerability found within Windows Kerberos. This flaw allows an authorized attacker to elevate their privileges when operating over an adjacent network. The vulnerability, classified under CWE-285 (Improper Authorization), stems from the Kerberos authentication protocol's failure to properly validate authorization controls. This enables attackers with initial network access to bypass authorization checks and gain elevated privileges within the affected Windows environment. This vulnerability is also referred to as "ResetNightmare".
- Description
- Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025
CVSS 3.1
- Type
- Primary
- Base score
- 8
- Impact score
- 5.9
- Exploitability score
- 2.1
- Vector string
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-285
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
4
KerberLoss (CVE-2026-25177) + ResetNightmare (CVE-2026-27912): two Kerberos logic flaws. Low-priv user → any account → domain admin → full domain takeover. Presented today at Black Hat USA by Semperis. https://t.co/QOdioHnQto #infosec #ActiveDirectory
@Ronin66Official
9 Aug 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Windows Kerberos'ta bulunan CVE-2026-27912 numaralı privilege escalation açığı için PoC Exploit yayınlandı. Açık, Windows Server 2012–2025 arası birçok sürümü etkiliyor ve saldırganın ağ üzerinden ayrıcalıklarını yükseltmesine olanak tanıyor. htt
@ridvanyagli
9 Aug 2026
1753 Impressions
6 Retweets
30 Likes
23 Bookmarks
1 Reply
0 Quotes
🚨 PoC released: CVE-2026-27912, a Windows Kerberos privilege escalation vulnerability, now has a public exploit. The flaw affects Windows Server 2012 and allows an authorized attacker to elevate privileges over an adjacent network. PoC: https://t.co/pfaHK1V3JM #Microsoft
@ThreatWire_
7 Aug 2026
1309 Impressions
2 Retweets
15 Likes
4 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
"matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"matchCriteriaId": "982DB0CA-5196-4E42-B2F7-994BE8179715",
"versionEndExcluding": "10.0.14393.9060",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"matchCriteriaId": "647CF9B5-8898-469B-9C09-D372A7843187",
"versionEndExcluding": "10.0.17763.8644",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"matchCriteriaId": "DC6837B7-5DFD-4AF7-B436-3C6FEF48BA60",
"versionEndExcluding": "10.0.20348.5020",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "55A1F3AB-5299-4495-9A73-FDA23C6FD88D",
"versionEndExcluding": "10.0.25398.2274",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ADF41A14-B9DA-4788-82A8-74DCDCD090E1",
"versionEndExcluding": "10.0.26100.32690",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]