Sceawere
Vulnerability Detail
CVE-2026-65777UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Windows Active Directory Inadequate Encryption Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 7h ago
- Vendor
- Microsoft
- Product
- Windows 11 version 23H2
- Attack Type
- CWE-326: Inadequate Encryption Strength
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-11T17:18:57.050Z",
"pubdate": "2026-08-11T17:18:57.050Z",
"executiveSummary": "An inadequate encryption strength vulnerability exists within Windows Active Directory, allowing an authenticated attacker to bypass a security feature over a network. This security flaw poses significant risk to directory service integrity and authorization controls. The vulnerability specifically affects Windows Active Directory implementations where weak cryptographic mechanisms are permitted during cryptographic validation or session establishment phases. Successful exploitation requires network access and an authorized attacker status within the targeted environment, enabling the circumvention of established security boundaries without triggering standard defensive alerts associated with cryptographic failures. The primary business and technical implication is the potential degradation of trust relationships and unauthorized access to protected resources or operations governed by the affected security feature. Mitigation requires identifying and restricting the use of weak cryptographic algorithms within the directory environment, enforcing robust encryption standards, and applying applicable vendor-supplied updates or configuration baselines designed to remediate cryptographic deficiencies.",
"technicalDetails": "The root cause of the vulnerability stems from the use or allowance of inadequate encryption strength within the cryptographic mechanisms utilized by Windows Active Directory. Specifically, the affected component fails to enforce sufficiently strong cryptographic parameters, allowing fallback or acceptance of weakened ciphers or key lengths during protocol negotiations or security feature validation routines over a network.\nThe attack flow proceeds as follows: First, an authorized attacker establishes a network connection to the target Windows Active Directory service. Second, during the authentication or security feature invocation phase, the attacker leverages the inadequate encryption strength supported by the system. By exploiting the weak cryptographic implementation, the attacker negotiates or forces the use of substandard encryption parameters. Third, the system accepts these weakened parameters due to insufficient validation constraints. Finally, the attacker leverages the resulting cryptographic weakness to manipulate or bypass the targeted security feature, achieving unauthorized execution states or circumventing access controls that rely on the integrity and strength of the encryption.\nThe vulnerability requires network exposure of the Windows Active Directory service and mandates that the attacker possesses initial authorization, meaning they have valid credentials or an established security context within the domain. No elevated privilege requirements beyond standard authorization are explicitly stated, but the exploitation directly results in the bypass of specific security features, potentially enabling further post-exploitation activities and lateral movement within the network."
}