ZeroHour

CVE-2021-42278

KEV ransomwaremass1

Privilege Escalation via sAMAccountName Spoofing in Microsoft Active Directory

CISA: Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

CVSS 3.1
7.5 high
EPSS
73%p99
Published
()
KEV added
AI analysis

CVE-2021-42278 is an elevation of privilege flaw in Microsoft Active Directory Domain Services (AD DS) caused by improper handling of changes to a computer account's sAMAccountName, allowing an attacker to 'spoof' a domain controller's name. A low-privileged authenticated user who can create or rename computer accounts (possible by default for ordinary domain users under MachineAccountQuota) renames a machine account to match a domain controller, obtains a Kerberos ticket for that name, and — typically chained with the related flaw CVE-2021-42287 — impersonates the domain controller to gain domain administrator rights. Successful exploitation yields full control of the Active Directory domain, which attackers, including ransomware operators, use to move laterally and deploy ransomware. Any organization running Active Directory on the affected Windows Server releases is exposed, though only servers with the AD DS role (domain controllers) reachable by an attacker with valid domain credentials are directly exploitable. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-11 with known ransomware use, and EPSS assigns a 73.3% probability of exploitation within 30 days.

What to do: Apply the Microsoft security updates for Active Directory Domain Services (released November 2021) to every domain controller, per CISA's required action. Until patched, restrict who can create or rename computer accounts (e.g., reduce MachineAccountQuota from the default 10) and audit domain controllers for renamed machine accounts and anomalous Kerberos tickets issued for domain controller names lacking the trailing '$'. Because CISA notes known ransomware use, hunt for signs of this flaw being chained with CVE-2021-42287 (the noPac technique) and for any new domain-admin activity on DCs.

Affected
microsoft Windows Server 2004 (AD DS)Affected AD DS builds per Microsoft advisory; source data lists no specific version ranges
microsoft Windows Server 2008 (AD DS)Affected AD DS builds per Microsoft advisory; source data lists no specific version ranges
microsoft Windows Server 2012 (AD DS)Affected AD DS builds per Microsoft advisory; source data lists no specific version ranges
microsoft Windows Server 2016 (AD DS)Affected AD DS builds per Microsoft advisory; source data lists no specific version ranges
microsoft Windows Server 2019 (AD DS)Affected AD DS builds per Microsoft advisory; source data lists no specific version ranges
microsoft Windows Server 2022 (AD DS)Affected AD DS builds per Microsoft advisory; source data lists no specific version ranges
microsoft Windows Server 20H2 (AD DS)Affected AD DS builds per Microsoft advisory; source data lists no specific version ranges
Estimated exposure
mass≈1 million+ domain controllers across hundreds of thousands of organizations (AD is near-universal in Windows enterprise environments) — Active Directory is the de facto directory service for nearly all Windows enterprise environments — industry surveys and internet scans put AD deployments at hundreds of thousands of organizations with domain controllers in the millions —…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Active Directory Domain Services Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Active Directory
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows server 2004, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 20h2
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

AI-powered attack exploited PaperCut flaws to hack 395 organizations

AI-driven campaign exploited PaperCut flaws CVE-2026-81578 and CVE-2026-82078, compromising 440 servers at 395 organizations in 48 countries.

GreyNoise reports a likely Russian-speaking threat actor used hundreds of AI agents combining OpenAI Codex and DeepSeek models to build, test, and refine exploits for CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF, launching the campaign on August 31. At least 440 PaperCut instances at 395 organizations across 48 countries were compromised, with the education sector accounting for roughly half of victims and the US most targeted. Attackers harvested credentials from 280 victims, obtained OS or domain secrets from 147, and gained admin privileges at 12 organizations, using LSASS dumping, pass-the-hash, noPac, and DCSync to dump NTDS.DIT. The adversary went from empty workspace to first RCE in under four hours, and compromised at least 11 organizations within 26 seconds once the campaign launched.

BleepingComputer · 5d agoExploit / PoC in the wildCVE-2026-81578CVE-2026-82078CVE-2021-42278+1 CVEs1· 1 read

Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers

AI-agent campaign exploited PaperCut CVE-2026-81578 and CVE-2026-82078, compromising 440 servers at 395 organizations and reaching Domain Admin in 12.

GreyNoise tracked a likely Russian-speaking actor that used AI agents (OpenAI Codex, a DeepSeek model) to exploit an authentication bypass (CVE-2026-81578) and unsafe-reflection RCE (CVE-2026-82078) in PaperCut NG/MF starting August 31, 2026. At least 440 servers across 395 organizations in 48 countries were compromised, with one US high school going from initial access to Domain Admin in seven minutes. Escalation relied on LSASS and registry credential harvesting, pass-the-hash, the noPac technique (CVE-2021-42278/CVE-2021-42287), new Domain Admin accounts, and DCSync to steal NTDS.DIT data. Operators staged registry hives, used Ligolo tunneling and certutil Base64 encoding for exfiltration, and one attempt was blocked by Cloudflare WAF.

GBHackers · 5d agoExploit / PoC in the wildCVE-2026-81578CVE-2026-82078CVE-2021-42278+1 CVEs1

Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

AI-orchestrated campaign exploited PaperCut NG/MF RCE (CVE-2026-81578/82078), compromising 440+ instances at 395 organizations in 48 countries.

GreyNoise tracked a likely Russian-speaking actor using AI (OpenAI Codex harness plus a DeepSeek model) to develop, test, and deploy exploits for PaperCut NG/MF (CVE-2026-81578, CVE-2026-82078) starting 31 August 2026. The actor compromised at least 440 PaperCut instances across 395 organizations in 48 countries, achieving domain admin at 12 victims — fastest time to domain admin was five minutes and a US high school was fully compromised in seven minutes. Attack paths involved LSASS memory and registry secret harvesting, pass-the-hash to domain controllers, noPac attacks, account additions to Domain Admins, and DCSync to exfiltrate full NTDS.DIT credential dumps. Impact scope suggests access development potentially for handoff, with prior PaperCut intrusions historically leading to extortion.

GreyNoise · 6d agoThreat actor in the wildCVE-2026-81578CVE-2026-82078CVE-2021-42278+1 CVEs1

Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide

A Russian-speaking actor used hundreds of AI agents to exploit PaperCut flaws, compromising 440 servers across 395 organizations in 48 countries.

GreyNoise's Global Observation Grid observed a Russian-speaking threat actor operating from IP 45.142.193.132 deploy hundreds of autonomous AI agents, built on OpenAI's Codex harness with a DeepSeek model, to exploit PaperCut NG/MF flaws CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe reflection RCE). At least 440 servers across 395 organizations in 48 countries were compromised; the US had 98 victims and educational institutions accounted for 204. The agents paired with Mimikatz, Certipy, Rubeus, and Impacket, escalated to domain admin in 12 of 440 cases, and executed DCSync to exfiltrate the full NTDS.DIT credential database.