CVE-2025-26647

I

mproper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*

History

13 Feb 2026, 20:16

Type Values Removed Values Added
Summary (en) Improper input validation in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network. (en) Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

10 Jul 2025, 15:57

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26647 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26647 - Vendor Advisory
First Time Microsoft windows Server 2016
Microsoft windows Server 2025
Microsoft windows Server 2022
Microsoft windows Server 2019
Microsoft windows Server 2008
Microsoft
Microsoft windows Server 2012
Microsoft windows Server 2022 23h2
CPE cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

11 Apr 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : 8.8

09 Apr 2025, 20:03

Type Values Removed Values Added
Summary
  • (es) La validación de entrada incorrecta en Windows Kerberos permite que un atacante no autorizado eleve privilegios en una red.

08 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 18:15

Updated : 2026-02-13 20:16


NVD link : CVE-2025-26647

Mitre link : CVE-2025-26647

CVE.ORG link : CVE-2025-26647


JSON object : View

CWE
CWE-20

Improper Input Validation