TGViewer
Whitehat Lab Whitehat Lab @wh_lab · 3.18K subscribers
Post #754 1.17K

Forwarded from 1N73LL1G3NC3

ResetNightmare

ResetNightmare (CVE-2026-27912) is a validation flaw in the Kerberos Change Password protocol that allows for resetting the password of any target user/computer account, without knowing the current one. The attack requires an unpatched domain controller, and the ability to write a userPrincipalName (UPN) on any account you control. Alternatively, the vulnerability can also be abused by an attacker having the ability to create new users/computers in any OU, as creating a user/computer allows you to get GenericWrite permissions over it.

Blog: Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover
  • ❤ 7
  • 👍 1
More from @wh_lab
  1. Sep 25, 2026Регистрация на SolarCTF открыта ☀️ Первые студенческие соревнования по кибербезопасности о…
  2. Sep 24, 2026📌 До ZeroNights 2026 осталась 1 неделя ! Время протестировать свою готовность к конференц…
  3. Sep 24, 2026⚙️ CVE PoC Search Engine Поисковик PoC'ов от наших китайских товарищей A modern, standalon…
  4. Sep 23, 2026💻 GPOddity The GPOddity tool aims to automate gPCFileSysPath attack vectors to exploit vu…
  5. Sep 22, 2026🔄 💻 evil-winrm-py 1.7.0 Аналог одноименной утилиты написанный на 😰 Python Python-based…
  6. Sep 21, 2026🔄🕸 humble v1.66 Быстрый анализатор HTTP заголовков, ориентированный на безопасность В 🐧…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →