Automatically translated.View original post

A security vulnerability was found on Windows Active Directory.

A security vulnerability was found on Windows Active Directory, allowing dangerous hackers to run down.

Windows operating systems are also popular in general use. They are also popular for managing in-house systems. Some versions of Windows provide management systems for professional use in-house, such as Windows Active Directory, a tool for managing users and resources. If this system is vulnerable, it often becomes a big deal.

According to a report by the Cyber Security News website, a vulnerability was detected on the Windows Active Directory on April 14. The vulnerability was coded CVE-2026-33826 with a danger rating or CVSS Score of up to 8.0, which is considered high and very dangerous. This vulnerability is a security vulnerability caused by improper input validation, resulting in hackers being able to run RCE or Remote Code Execution. The code is grounded with the same level of RPC privileges ( Remote Procedure Call results in hackers taking control of Windows Active Directory and modifying Configuration settings. In addition, this vulnerability can be easily used without very high technical knowledge. The victim side does not need to interact (Interaction) for the vulnerability to work.

This vulnerability is also limited: it is a vulnerability that requires only close-up, which means that hackers must be people within the system or in the target organization, and they must be allowed to access the Restricted Active Directory in the first place to access it. It is called an attack that can only occur when the organization has a "salt-worm" group that uses the vulnerability.

This vulnerability appears on many versions of Windows Server, but Microsoft has released updates to plug it quickly. Updates for the versions of Windows Server that plug it include the following:

Windows Server 2012 R2 (KB5082126)

Windows Server 2016 (KB5082198)

Windows Server 2019 (KB5082123)

Windows Server 2022, including the 23H2 Edition (KB5082142 and KB5082060)

Windows Server 2025 (KB5082063)

# Trending # Lemon 8 Howtoo # lemon 8 diary # Windows # freedomhack

5/6 Edited to

... Read moreจากประสบการณ์การจัดการระบบ Windows Active Directory ในองค์กร พบว่าช่องโหว่ความปลอดภัยที่เรียกว่า CVE-2026-33826 นั้นถือเป็นภัยคุกคามที่ต้องให้ความสำคัญสูงสุด เนื่องจากเป็นช่องโหว่ชนิด Remote Code Execution (RCE) ที่แฮกเกอร์สามารถนำไปใช้เข้าควบคุมระบบและดัดแปลงการตั้งค่าต่าง ๆ ได้อย่างอิสระ ซึ่งส่งผลกระทบรุนแรงต่อความปลอดภัยของข้อมูลและระบบเครือข่าย ในทางปฏิบัติ ช่องโหว่นี้เกิดจากข้อผิดพลาดในการตรวจสอบความถูกต้องของข้อมูลที่ป้อนเข้าไป ทำให้ข้อมูลที่ถูกจัดการไม่ถูกกรองหรือตรวจสอบอย่างเหมาะสม ส่งผลให้แฮกเกอร์ที่อยู่ในเครือข่ายองค์กรสามารถใช้ช่องโหว่นี้โจมตีได้ง่ายโดยไม่ต้องมีความรู้เชิงลึกด้านเทคนิคมากนัก และไม่ต้องรอปฏิสัมพันธ์จากผู้ใช้งาน ซึ่งถือเป็นความเสี่ยงที่อันตรายมาก แม้ช่องโหว่นี้จะมีข้อจำกัดว่าแฮกเกอร์ต้องมีสิทธิ์เข้าถึง Active Directory ในระดับที่ถูกจำกัดอยู่ก่อนแล้ว แต่ในองค์กรที่มีผู้ใช้งานมากหรือมีความซับซ้อนทางโครงสร้างผู้ใช้งาน (User) ปัญหานี้ก็สามารถเกิดขึ้นขึ้นได้ เพราะอาจมีบุคคลภายในที่ไม่หวังดีหรือถูกโจมตีโดยมัลแวร์ตัวอื่นนำช่องโหว่ไปใช้ประโยชน์ได้ สิ่งที่ผมแนะนำสำหรับหน่วยงาน IT คือการตรวจสอบและอัปเดตแพตช์ความปลอดภัยของ Windows Server อย่างรวดเร็ว จากที่แนะนำไว้ ในเวอร์ชัน 2012 R2, 2016, 2019, 2022 และ 2025 นั้นต้องหมั่นอัปเดตแพตช์ให้ครอบคลุม นอกจากนี้ ควรมีการกำหนดสิทธิ์ผู้ใช้งานใน Active Directory อย่างเข้มงวด ลดสิทธิ์ที่ไม่จำเป็น และติดตามกิจกรรมที่น่าสงสัย เช่น การเปลี่ยนแปลงคอนฟิกโดยไม่ได้รับอนุญาต เพื่อป้องกันการใช้ช่องโหว่ในทางที่ผิด สุดท้าย การจัดฝึกอบรมให้ทีมงานรับรู้ถึงความเสี่ยงในช่องโหว่ดังกล่าว และให้ความรู้การรักษาความปลอดภัยในระบบเครือข่าย ก็เป็นอีกทางหนึ่งที่ช่วยลดโอกาสการถูกโจมตีด้วยช่องโหว่นี้อย่างได้ผล