Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2025-26685 – Spoofing to Elevate Privileges with Microsoft Defender for Identity

Summary

CVE-2025-26685 lets an unauthenticated attacker on the local network coerce the Defender for Identity sensor into NTLM authentication, capturing the DSA's Net-NTLM hash for cracking or relay attacks.
CVE
CVE-2025-26685
Published
Collected

original ↗