Cyber Security News

Windows 11 And Server 2025 Will Start Caching Plaintext Credentials By Enabling WDigest Authentication

Cybersecurity threats are rapidly evolving; even advanced operating systems like Windows 11 and Windows Server 2025 can have vulnerabilities due to legacy configurations.

Horizon Secure highlighted a concerning feature: WDigest authentication, which can be enabled to cache plaintext passwords in memory, potentially exposing users to credential theft.

Disabled by default since Windows 10 version 1703, WDigest was designed to store hashed credentials for compatibility with older applications.

However, a simple registry modification can reactivate it, allowing Windows to retain unencrypted passwords during logon sessions.

The registry key in question HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest\UseLogonCredential set to 1 takes effect immediately upon the next user logon, without requiring a system reboot.

This means sensitive credentials linger in process memory, ripe for extraction by malware or attackers with local access.

Attackers covet plaintext credentials because they bypass the need for cracking hashes, enabling quicker lateral movement across networks.

Tools like Mimikatz have long exploited WDigest for this purpose, and despite Microsoft’s hardening efforts, such as protecting the Local Security Authority Subsystem Service (LSASS) process in Windows 11, vulnerabilities persist.

LSASS safeguards prevent easy dumping of credentials, but re-enabling WDigest undermines these protections by storing passwords openly.

Many organizations overlook this risk, especially those running Windows 11 Pro editions. Advanced features like Credential Guard, which virtualizes LSASS for isolation, are exclusive to Enterprise and Education versions.

Without it, Pro users remain vulnerable if legacy apps demand WDigest compatibility, a common scenario in mixed environments.

Mitigations

Fortunately, free built-in tools can counter this threat. The Protected Users group in Active Directory blocks WDigest caching and other weak authentication methods for high-privilege accounts.

Yet, adoption remains low; security audits often reveal privileged users outside this group, leaving doors ajar.

Experts urge immediate checks: Scan for the WDigest registry key and audit group memberships. For broader defense, enable multi-factor authentication and monitor for anomalous memory access.

While Microsoft continues to phase out legacy auth, user vigilance is key to avoiding plaintext pitfalls. As cyber threats target Windows ecosystems, this reminder underscores that security defaults are strong, but misconfigurations can unravel them swiftly.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago