CVE-2025-26685 – Spoofing to Elevate Privileges with Microsoft Defender for Identity
netspi.com | vulnerability | CVE-2025-26685 | #active-directory | #privilege-escalation | #ntlm | #spoofing | #cve-2025-26685 | #microsoft-defender-for-identity
Summary
CVE-2025-26685 lets an unauthenticated attacker on the local network coerce the Defender for Identity sensor into NTLM authentication, capturing the DSA's Net-NTLM hash for cracking or relay attacks.
- CVE
- CVE-2025-26685
- Published
- Collected
Skip to content