CVE-2025-11561
8.8Red Hat · System Security Services Daemon (SSSD)
A flaw in SSSD allows an attacker with permission to modify AD attributes to impersonate privileged users via an improper fallback to the an2ln plugin, enabling unauthorized access or escalation.
Executive summary
A critical vulnerability in the SSSD Active Directory integration allows authenticated attackers to perform privilege escalation and impersonate administrative users on Linux hosts.
Vulnerability
This issue involves Improper Privilege Management (CWE-269) within the SSSD Kerberos local authentication plugin. The vulnerability occurs when the system incorrectly falls back to the an2ln plugin, allowing an attacker with local or domain-level permissions to modify specific Active Directory attributes and bypass authentication security controls.
Business impact
The ability for an attacker to impersonate privileged users poses a significant risk to organizational integrity and data security. By successfully exploiting this flaw, unauthorized actors can gain administrative control over domain-joined Linux systems, leading to full system compromise. With a CVSS score of 8.8, this vulnerability represents a high-severity threat that could facilitate lateral movement and the exfiltration of sensitive organizational data.
Remediation
Immediate Action: Update SSSD to the corrected versions provided by Red Hat, specifically ensuring packages are at or above the versions listed in the relevant RHSA advisories (e.g., 2.10.2-3.el10_0.3 or 2.11.1-2.el10_1.1 for RHEL 10).
Proactive Monitoring: Review system authentication logs for unusual login patterns or modifications to Active Directory user attributes that might indicate an attempt to exploit user impersonation.
Compensating Controls: Restrict permissions for modifying Active Directory attributes such as userPrincipalName and samAccountName to only the most trusted administrative accounts to reduce the attack surface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a clear path for privilege escalation on Linux environments integrated with Active Directory. Given the potential for total system compromise, administrators should prioritize the deployment of the provided patches across all affected Linux infrastructure. Failure to remediate this issue leaves domain-joined hosts susceptible to unauthorized administrative access.
More Red Hat CVEs
Sources
Originally found and disclosed by Red Hat would like to thank Zavier Lee for reporting this issue., per the CVE Program record.
- RHSA-2025:19610 Vendor advisory
- RHSA-2025:19847 Vendor advisory
- RHSA-2025:19848 Vendor advisory
- RHSA-2025:19849 Vendor advisory
- RHSA-2025:19850 Vendor advisory
- RHSA-2025:19851 Vendor advisory
- RHSA-2025:19852 Vendor advisory
- RHSA-2025:19853 Vendor advisory