CVE-2025-11561
HIGHDescription
A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.
CVSS v3 Vector
Exploitability
Impact
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploit Intelligence
Moderate risk: more likely to be exploited than 51% of all known CVEs.
References
- https://access.redhat.com/errata/RHSA-2025:19610
- https://access.redhat.com/errata/RHSA-2025:19847
- https://access.redhat.com/errata/RHSA-2025:19848
- https://access.redhat.com/errata/RHSA-2025:19849
- https://access.redhat.com/errata/RHSA-2025:19850
- https://access.redhat.com/errata/RHSA-2025:19851
- https://access.redhat.com/errata/RHSA-2025:19852
- https://access.redhat.com/errata/RHSA-2025:19853
- https://access.redhat.com/errata/RHSA-2025:19854
- https://access.redhat.com/errata/RHSA-2025:19859
- https://access.redhat.com/errata/RHSA-2025:20954
- https://access.redhat.com/errata/RHSA-2025:21020
- https://access.redhat.com/errata/RHSA-2025:21067
- https://access.redhat.com/errata/RHSA-2025:21329
- https://access.redhat.com/errata/RHSA-2025:21795
- https://access.redhat.com/errata/RHSA-2025:22256
- https://access.redhat.com/errata/RHSA-2025:22265
- https://access.redhat.com/errata/RHSA-2025:22277
- https://access.redhat.com/errata/RHSA-2025:22529
- https://access.redhat.com/errata/RHSA-2025:22548
- https://access.redhat.com/errata/RHSA-2025:22724
- https://access.redhat.com/errata/RHSA-2025:23113
- https://access.redhat.com/errata/RHSA-2026:0316
- https://access.redhat.com/errata/RHSA-2026:0677
- https://access.redhat.com/security/cve/CVE-2025-11561
- https://blog.async.sg/kerberos-ldr
- https://bugzilla.redhat.com/show_bug.cgi?id=2402727
- https://github.com/SSSD/sssd/issues/8021
Find and fix vulnerabilities across your fleet
TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
Start freeThis product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-03-19.