LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-42287: Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 11, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 2, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-42287 to its Known Exploited Vulnerabilities catalog on Apr 11, 2022, with a federal patch deadline of May 2, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

CVE-2021-42287 is a privilege escalation vulnerability in Microsoft Active Directory Domain Services. An attacker who can already operate in a domain environment may be able to gain higher privileges than intended. CISA notes known ransomware use associated with this issue, so domain controllers and related Active Directory infrastructure deserve prompt attention. Confirm all product, version, and fix details against the Microsoft vendor advisory before acting.

How it works

The weakness is classified as CWE-269 (Improper Privilege Management). In plain terms, Active Directory Domain Services does not correctly enforce the boundary between lower-privileged and higher-privileged operations under certain conditions. An attacker who already has some foothold in the domain can abuse that gap to elevate privileges.

Public detail on the exact abuse path is limited in the provided record. Treat it as a classic domain privilege-escalation flaw: once elevated, the attacker can typically create or modify accounts, alter group membership, or take further control of domain resources. Do not rely on unconfirmed exploit write-ups; validate behavior and detection guidance against the official Microsoft advisory.

Am I affected? How to find it in your systems

This affects Microsoft Active Directory Domain Services, which runs on domain controllers in Windows Server environments that host AD DS. Inventory every domain controller, including those in child domains, forests, and any RODCs or staging systems.

If you cannot map a system to a patched build listed by Microsoft, treat it as potentially affected until confirmed otherwise.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

Do not substitute unofficial patches or registry tweaks for the vendor update unless Microsoft explicitly documents them as supported mitigations.

If you can't patch immediately

Reduce exposure until the official update can be installed.

These steps lower risk; they do not replace the vendor patch.

If your data may have been exposed

Privilege-escalation flaws in Active Directory that are tied to ransomware activity can lead to full domain compromise and data theft or encryption. If you suspect exploitation, isolate affected systems, preserve logs, reset potentially compromised credentials (especially privileged ones), and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data to see whether your identities already appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Active Directory
WeaknessCWE-269
Added to CISA KEVApr 11, 2022
Federal patch deadlineMay 2, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities