Two types of ACLs:
Three main types of ACEs:
Dangerous AD ACEs:
ForceChangePassword abused with Set-DomainUserPasswordAdd Members abused with Add-DomainGroupMemberGenericAll abused with Set-DomainUserPassword or Add-DomainGroupMemberGenericWrite abused with Set-DomainObjectWriteOwner abused with Set-DomainObjectOwnerWriteDACL abused with Add-DomainObjectACLAllExtendedRights abused with Set-DomainUserPassword or Add-DomainGroupMemberAddSelf abused with Add-DomainGroupMember