A Windows Kerberos Elevation of Privilege Vulnerability affecting Microsoft Windows Server 2012 versions The flaw affects unpatched Windows domain controllers, identified as CVE-2026-27912 with a CVSS score of 8.0, allows an attacker to reset any Active Directory account password without knowing the old one, granting SYSTEM privileges upon successful abuse. This flaw sits in the Windows Kerberos Change Password protocol and affects unpatched Windows domain controllers, requiring the attacker to be inside the same restricted Active Directory domain. The vulnerability details and a proof-of-concept exploit code are now openly available, raising the stakes for defenders and putting unpatched domain controllers at real risk of full domain compromise. An attacker who wins the exploit could gain SYSTEM privileges, which can mean full domain compromise.
We recommend you to update Microsoft Windows Server 2012 to given version link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27912[/subscribe_to_unlock_form]
A Windows Kerberos Elevation of Privilege Vulnerability affecting Microsoft Windows Server 2012 versions The flaw affects unpatched Windows domain controllers, identified as CVE-2026-27912 with a CVSS score of 8.0, allows an attacker to reset any Active Directory account password without knowing the old one, granting SYSTEM privileges upon successful abuse. This flaw sits in the Windows Kerberos Change Password protocol and affects unpatched Windows domain controllers, requiring the attacker to be inside the same restricted Active Directory domain. The vulnerability details and a proof-of-concept exploit code are now openly available, raising the stakes for defenders and putting unpatched domain controllers at real risk of full domain compromise. An attacker who wins the exploit could gain SYSTEM privileges, which can mean full domain compromise.
We recommend you to update Microsoft Windows Server 2012 to given version link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27912[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]