CVE-2025-11561 - CVE House
Back to Database
Status published High CVE-2025-11561

Sssd: sssd default kerberos configuration allows privilege escalation on ad-joined linux systems

Vulnerability Description

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11561

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Red Hat would like to thank Zavier Lee for reporting this issue.

Affected Vendor

Affected Software

Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift Container Platform 4.12, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift Container Platform 4.16, Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift Container Platform 4.18, Red Hat OpenShift Container Platform 4.19, Red Hat OpenShift Container Platform 4.20, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, Red Hat Enterprise Linux 6
Vulnerable Versions:
0, 0:2.10.2-3.el10_0.3, 0:2.11.1-2.el10_1.1, 0:1.16.5-10.el7_9.17, 0:2.9.4-5.el8_10.3, 0:2.2.3-20.el8_2.3, 0:2.4.0-9.el8_4.4, 0:2.6.2-4.el8_6.4, 0:2.8.2-4.el8_8.3, 0:2.9.7-4.el9_7.1, 0:2.6.2-4.el9_0.4, 0:2.8.2-5.el9_2.6, 0:2.9.4-6.el9_4.4, 0:2.9.6-4.el9_6.3, 412.86.202601061735-0, 413.92.202601130113-0, 414.92.202511122212-0, 415.92.202512100122-0, 416.94.202512030118-0, 417.94.202511260612-0, 418.94.202511170715-0, 4.19.9.6.202511252219-0, 4.20.9.6.202511252309-0, sha256:6b79ed10423d954d21dd24c9cb1cf507f6e02c2942ace7fa30cf7af2ffaeb631, sha256:04a48d31f7336e0d5958eed1ddb1a117148f791baccef4e6e08943181e6794c8

Timeline

Official Publish: October 9th, 2025
Last Modified: March 19th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)