Improper Authentication Vulnerability in Microsoft Defender for Identity
CVE-2025-26685

6.5MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
13 May 2025

Badges

đź“° News Worthy

What is CVE-2025-26685?

A flaw has been identified in Microsoft Defender for Identity where improper authentication mechanisms can be exploited by unauthorized attackers. This vulnerability allows malicious entities to perform spoofing attacks over adjacent networks, potentially compromising sensitive data and system integrity. It is crucial for organizations using Microsoft Defender for Identity to understand the implications of this vulnerability and take necessary precautions to secure their environments.

Affected Version(s)

Microsoft Defender for Identity Unknown

News Articles

Update Windows Now — Microsoft Confirms System Takeover Danger

Microsoft has issued a warning that Windows hackers could gain system privileges using this authentication relay attack — an update is available; apply now.

2 weeks ago

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • đź“°

    First article discovered by Forbes

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-26685 : Improper Authentication Vulnerability in Microsoft Defender for Identity