Pentera
Active Directory SID Locking Exploit Analysis
Pages
16
Time to read
16 mins
Publication
Language
English
Pages
16
Time to read
16 mins
Publication
Language
English
This technical report examines the potential exploit of Security Identifier (SID) limits within Microsoft Active Directory (AD) that may lead to a Denial of Service (DoS) attack. It outlines how an attacker with minimal privileges can lock out users, including domain administrators, by manipulating access tokens overloaded with group memberships. The report details the mechanisms of this attack, emphasizing the significance of SID limits in AD, and describes the process through which a user can be added to multiple groups, exceeding the SID threshold. Additionally, it discusses the implications of having a user create security groups and the ease with which they can affect the entire domain. Strategies for prevention and mitigation of this risk are also provided, making it essential for IT professionals and system administrators to understand this vulnerability to secure their networks effectively. A responsible disclosure process was maintained throughout, as the issue was communicated to Microsoft who did not classify it as requiring immediate action.