CVE-2025-4404: Insufficient Granularity of Access Control
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
AI Analysis
Technical Summary
This vulnerability in FreeIPA involves a failure to validate the uniqueness of the krbCanonicalName for the admin account by default. Attackers can create services with the same canonical name as the REALM admin, allowing them to retrieve Kerberos tickets containing admin@REALM credentials. This leads to privilege escalation from host to domain admin, enabling administrative actions and potential data exfiltration within the REALM. The CVSS 3.1 base score is 9.1, indicating critical severity. Red Hat has released security updates for Red Hat Enterprise Linux 9 to fix this issue.
Potential Impact
Exploitation of this vulnerability allows an attacker with host-level access to escalate privileges to domain admin within the FreeIPA-managed REALM. This grants the attacker administrative capabilities over the identity management system, potentially leading to unauthorized access to sensitive data and data exfiltration. The vulnerability compromises confidentiality, integrity, and availability of the affected environment.
Mitigation Recommendations
Red Hat has released official security updates addressing CVE-2025-4404 for Red Hat Enterprise Linux 9, including various architectures and update services. Users should apply these updates promptly following Red Hat's guidance at https://access.redhat.com/articles/11258. The vendor advisory classifies this update as Important and provides detailed package versions for remediation. Patch status is confirmed as available. No additional mitigation steps are specified beyond applying the official updates.
CVE-2025-4404: Insufficient Granularity of Access Control
Description
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
CVSS v3.1
Score 9.1critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in FreeIPA involves a failure to validate the uniqueness of the krbCanonicalName for the admin account by default. Attackers can create services with the same canonical name as the REALM admin, allowing them to retrieve Kerberos tickets containing admin@REALM credentials. This leads to privilege escalation from host to domain admin, enabling administrative actions and potential data exfiltration within the REALM. The CVSS 3.1 base score is 9.1, indicating critical severity. Red Hat has released security updates for Red Hat Enterprise Linux 9 to fix this issue.
Potential Impact
Exploitation of this vulnerability allows an attacker with host-level access to escalate privileges to domain admin within the FreeIPA-managed REALM. This grants the attacker administrative capabilities over the identity management system, potentially leading to unauthorized access to sensitive data and data exfiltration. The vulnerability compromises confidentiality, integrity, and availability of the affected environment.
Mitigation Recommendations
Red Hat has released official security updates addressing CVE-2025-4404 for Red Hat Enterprise Linux 9, including various architectures and update services. Users should apply these updates promptly following Red Hat's guidance at https://access.redhat.com/articles/11258. The vendor advisory classifies this update as Important and provides detailed package versions for remediation. Patch status is confirmed as available. No additional mitigation steps are specified beyond applying the official updates.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- redhat
- Date Reserved
- 2025-05-06T22:17:12.623Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2025:9184","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9185","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9186","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9187","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9188","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9189","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9190","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9191","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9192","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9193","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9194","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2025-4404","vendor":"Red Hat"}]
Threat ID: 68517269a8c921274385c3c1
Added to database: 06/17/2025, 13:49:29 UTC
Last enriched: 07/02/2026, 21:56:45 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 174
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.