Join our Newsletter — 33% off our NHI Course

What are the signs that an Active Directory environment may still be vulnerable to CVE-2021-42287 and CVE-2021-42278?

A vulnerable environment is one where unprivileged users can complete the ticket request sequence and receive elevated access after spoofing a domain administrator account. The clearest operational sign is that a test account can move from ordinary user status to domain admin conditions without being blocked. If that path exists, the domain controller remains exposed and should be treated as unsafe.

What a vulnerable Active Directory path looks like in practice

The clearest sign is that the domain still accepts the vulnerable ticket request sequence without stopping an unprivileged caller. In practical terms, a low-privilege test account should not be able to progress from ordinary user context into a path that yields elevated domain-admin style access. If that sequence still completes, the environment remains exposed.

A second sign is that the controller does not correctly reject spoofed or ambiguous account naming during the request flow. These flaws are dangerous because the attack is not a noisy password guess, it is a name-matching and ticketing weakness that can let an attacker turn a normal identity into a privileged one if the controls are still loose.

Operational checks that indicate exposure remains

Look for repeated evidence that Kerberos-related administrative requests are accepted when they should fail. If test activity can still obtain the expected ticket behavior, or if a renamed or spoofed account is treated as the administrator account it resembles, the domain is likely still vulnerable.

Another useful indicator is that the environment has not been hardened to block privilege escalation paths across domain controllers, account naming, and ticket issuance. Active Directory and Entra ID Hardening Guide is useful here because it frames the controls that should prevent these attack paths from remaining reachable.

It also helps to compare the vulnerable behavior against known exploitation patterns in the wider identity ecosystem. The 52 NHI Breaches Report shows how credential and access abuse often turns a small weakness into a larger compromise, which is the same escalation logic at work when a low-privilege identity can unexpectedly obtain elevated reach.

How to interpret the result safely

If a simple test account can complete the vulnerable sequence and reach elevated access, treat the domain controller as unsafe even if no active abuse has been observed. Absence of alerts does not mean absence of risk, because this issue can fail silently until someone exercises the exact path.

Where the test fails only intermittently, assume the environment is still inconsistent rather than safe. That usually means one of the necessary protections is partially deployed, misconfigured, or not covering every controller, which is enough to leave a live attack path available.

Risk and Threat Considerations

The risk is not limited to one misissued ticket. If the vulnerable behavior is still present, an attacker with only ordinary domain access can turn naming confusion and ticket handling into domain-level compromise, which makes the issue especially severe in environments that still trust legacy AD behavior.

Failure mechanism: The attacker abuses account spoofing and Kerberos ticket handling so the domain controller mistakes or accepts a privileged identity path that should have been denied, allowing escalation from low privilege to elevated access.

Impact: Once that path is available, the attacker may obtain domain administrator conditions, move laterally, access sensitive systems, and use the compromised directory trust to deepen persistence across the environment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack surface, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
MITRE ATT&CK T1558 — Steal or Forge Kerberos Tickets Kerberos ticket abuse is central to this AD escalation pattern.
Recommendation — Map the observed path to Kerberos ticket abuse and hunt for forged or replayed ticket activity.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management The vulnerability hinges on broken handling of authentication material and ticket lifecycle.
AC-6 — Least Privilege The issue becomes critical when ordinary users can reach privileged access.
Recommendation — Review authenticator handling and rotate any credentials or secrets tied to the exposed path. Remove excess privileges and block any path that lets standard users reach domain-admin conditions.
NIST CSF 2.0 PR.AA-05 — Access Permissions and Authorizations Are Defined, Managed, Enforced, and Reviewed This issue is an authorization failure that should be prevented and reviewed.
Recommendation — Enforce and review access decisions so unprivileged users cannot trigger privileged behavior.
ISO/IEC 27001:2022 A.5.15 — Access control The subject is fundamentally about preventing unauthorized directory access.
Recommendation — Tighten access control rules and verify they block the spoofing-to-admin escalation path.

Practitioner Guidance

What to verify: Confirm that a non-privileged test account cannot reproduce the request sequence end to end. The decisive check is not whether the domain is “patched somewhere,” but whether the exact path is blocked on every relevant controller and naming edge case.

Common mistake: Teams often validate only normal admin workflows and miss the abuse case where a spoofed or renamed account is accepted. That creates false confidence because the vulnerable path can remain untouched even when routine administration appears healthy.

Practitioner takeaway: Treat any successful privilege jump from an ordinary account as proof of exposure, then verify the failure mode at the controller and ticketing layers rather than assuming the issue is resolved by partial hardening.