logo

Microsoft to fix two major attack methods for hackers

ID: 37bf47aa-dc49-530d-a7e7-3a099fcfcf9b

STIX ID: report--37bf47aa-dc49-530d-a7e7-3a099fcfcf9b

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2025-03-25

Date Updated: 2026-05-01

...
...

Executive summary: The report outlines two long-standing Windows post-exploitation weaknesses — Group Policy Preferences (GPP) cpassword exposure in SYSVOL and Pass‑the‑Hash credential reuse — that enable attackers to escalate privileges and move laterally. It references historical disclosures, public tooling (Metasploit), and Microsoft advisories/patches, while noting that mitigations may not fully eliminate the risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.