CVE-2025-29810: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
Other sources
Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22523Patch KB5055557 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25423Patch KB5055581 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.3775Patch KB5055523 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.5189Patch KB5055528 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.5737Patch KB5055518 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1551Patch KB5055527 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.5189Patch KB5055528 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.23220Patch KB5055596 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.5737Patch KB5055518 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27670Patch KB5055570 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7969Patch KB5055521 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20978Patch KB5055547 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.3453Patch KB5055526 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.7136Patch KB5055519
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29810?
CVE-2025-29810 has a high severity rating due to its potential for privilege escalation in Active Directory.
How do I fix CVE-2025-29810?
To fix CVE-2025-29810, ensure that you apply the latest security patches provided by Microsoft for the affected software.
What systems are affected by CVE-2025-29810?
CVE-2025-29810 affects multiple Microsoft Windows products including Windows Server, Windows 10, and Windows 11.
Can CVE-2025-29810 be exploited remotely?
Yes, CVE-2025-29810 can be exploited over a network by authorized attackers.
What types of attacks can result from CVE-2025-29810?
CVE-2025-29810 can lead to unauthorized privilege escalation within Active Directory environments.