H3-2022-0095
Password Reuse Found in Active Directory Services Database (NTDS)
Category | CREDENTIALS |
Base Score | 8.0 |
Description
After obtaining domain administrator access, NodeZero dumped all domain user NTLM hashes from a domain controller. At least two active domain users were found sharing the same password. View the proof for a summary report.
Impact
Attackers can exploit password reuse to discover new credentials and move laterally through the environment, gaining access to more data, applications, and hosts.