
CVE-2021-42278 noPac: Domain User to Domain Admin
CVE-2021-42287 and CVE-2021-42278 are Active Directory privilege escalation vulnerabilities patched in November 2021. Chained together in the 'noPac' exploit, they allowed any authenticated domain user to impersonate a Domain Controller via Kerberos, obtaining a TGT with domain admin-equivalent privileges, a complete Active Directory takeover from a standard user account with no additional tooling beyond a domain login.
