Micropatches released for "KerberLoss" Active Directory Domain Services Elevation of Privilege Vulnerability (CVE-2026-25177)

Mitja KolsekAug 17, 2026
Micropatches released for "KerberLoss" Active Directory Domain Services Elevation of Privilege Vulnerability (CVE-2026-25177)

Earlier this month, security researcher Shai Laron of Semperis published a detailed article on a privilege escalation vulnerability in Kerberos they dubbed "KerberLoss." This vulnerability allows an attacker with write permissions on the servicePrincipalName property of a domain user or computer account under their control to cause denial of service, force Kerberos authentication to fall back to NTLM, or hijack services. (Note that merely having permission to create a new domain computer account is not sufficient, because the creator does not automatically receive the required WriteSPN permission on that account.)

Microsoft patched this issue with March 2026 Windows Updates and assigned it CVE-2026-25177. Shai's article allowed us to reproduce the issue and create patches for legacy Windows users.

The Vulnerability 

The vulnerability lies in Active Directory Domain Services' handling of Unicode characters when enforcing the uniqueness of users' and computers' servicePrincipalName attributes.

Microsoft's Patch

Microsoft fixed the issue by correctly enforcing servicePrincipalName uniqueness when SPNs are added or modified.

Our Patch

Our patch is logically identical to Microsoft's.

Micropatch Availability

Micropatches were written for the following security-adopted Windows versions:

  1. Windows Server 2008 R2 - fully updated with ESU 2, ESU 3 or ESU 4

  2. Windows Server 2012 - fully updated with no ESU, with ESU 1 or ESU 2

  3. Windows Server 2012 R2 - fully updated with no ESU, with ESU 1 or ESU 2

 

Based on our research, Windows Server 2008 R2 with no ESU or with ESU 1 unfortunately do not have any uniqueness validation in place as this (fairly complex) feature was implemented later, and there was no flaw for us to patch there.

Micropatches have already been distributed to, and applied on, all affected online computers with 0patch Agent in PRO or Enterprise accounts (unless Enterprise group settings prevented that).

New vulnerabilities like these are discovered regularly, and attackers can eventually learn about and exploit them. If you're using Windows that aren't receiving official security updates anymore, 0patch will help prevent these vulnerabilities from being exploited on your computers - and you won't even have to know or care about these things. 

We'd like to thank Shai Laron of Semperis for sharing their analysis, which allowed us to create patches for Windows versions that are no longer receiving official updates from Microsoft.

If you're new to 0patch, create a free account in 0patch Central, start a free trial, then install and register 0patch Agent. Everything else will happen automatically. No computer reboot will be needed.

Did you know 0patch security-adopted Windows 10 and Office 2016 and 2019 when they went out of support in October 2025, allowing you to keep using them for at least 3 more years (5 years for Windows 10)? Read more about it here and here

Note that we will soon security-adopt the following products:

Windows 10 22H2 with Extended Security Updates year 1: October 2026

Windows Server 2012 with Extended Security Updates year 3: October 2026

Windows Server 2012 R2 with Extended Security Updates year 3: October 2026

Microsoft Office 2021: October 2026

Windows 11 23H2 (E): November 2026

Windows Server 2016: January 2027

To learn more about 0patch, please visit our Help Center.