PT-2025-32855 · Wing Ftp+4 · Wing Ftp Server+6
Yug0Rd
+1
·
Published
2025-08-12
·
Updated
2026-04-14
·
CVE-2025-53779
CVSS v2.0
9.0
High
| AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Kerberos versions prior to the August 2025 updates
Description
A relative path traversal issue in the Windows Kerberos protocol allows an authorized attacker to elevate privileges over a network. This can be achieved by abusing delegated Managed Service Accounts (
dMSA), potentially granting the attacker full control over the corporate network, including domain administrator rights. This zero-day issue was actively exploited before the release of a security update.Recommendations
Install the August 2025 updates.
Review permissions on Organizational Units, containers, and
dMSA objects.
Restrict the creation and modification of dMSA and their migration link attributes to Tier 0 administrators.Fix
RCE
LPE
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Apple
Cisco Ise
Google Chrome
Windows
Windows Kerberos
Wing Ftp Server