LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-42278: Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 11, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 2, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-42278 to its Known Exploited Vulnerabilities catalog on Apr 11, 2022, with a federal patch deadline of May 2, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

CVE-2021-42278 is a privilege escalation vulnerability in Microsoft Active Directory Domain Services. An attacker who can already interact with a domain environment may be able to raise their privileges beyond what their account should allow. Because Active Directory underpins authentication and authorization across most Windows enterprise networks, successful abuse can give an adversary broad control of domain resources. CISA notes that this vulnerability has been used by ransomware operators, which raises the urgency of finding and fixing affected systems.

Public technical detail is limited beyond the classification as an unspecified privilege-escalation issue tied to improper input validation (CWE-20). Defenders should treat the vendor advisory as the authoritative source for exact scope, fixed builds, and any additional indicators.

How it works

The underlying weakness is CWE-20 (Improper Input Validation). In Active Directory Domain Services this class of flaw typically means the service does not adequately check or sanitize certain inputs before acting on them. An attacker who already has a foothold—commonly a low-privileged domain user or a compromised machine account—can supply crafted input that the service processes in a way that elevates the attacker’s rights.

Exact exploitation mechanics are not fully detailed in the public summary; they must be confirmed against the Microsoft advisory. In general, privilege-escalation paths against Domain Services let an adversary move from ordinary user context toward higher-privileged roles (for example domain administrator equivalents), after which they can create accounts, modify group membership, dump credentials, or deploy ransomware. Because the service is central to the domain, the impact is rarely limited to a single host.

Am I affected? How to find it in your systems

Active Directory Domain Services runs on Windows Server domain controllers. Any organization that maintains an on-premises or hybrid AD forest should assume potential exposure until inventory and patch status are verified.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2021-42278 exactly as directed in the vendor advisory and in CISA’s required action (“Apply updates per vendor instructions”). Test the updates in a representative lab or pilot OU if your change-control process requires it, then roll them out to all domain controllers promptly.

If you can't patch immediately

Until every domain controller is updated, reduce the attack surface and increase detection confidence.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities in Active Directory frequently precede ransomware deployment and large-scale data theft. If you have evidence of compromise or simply want to check whether credentials tied to your organization already appear in known breach corpora, run a free exposure scan of your email addresses against published breach data sets and follow your incident-response plan for any confirmed hits.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Active Directory
WeaknessCWE-20
Added to CISA KEVApr 11, 2022
Federal patch deadlineMay 2, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities