HIGH
CVE-2022-26923
CVSS
8.8
KEV
Description
Active Directory Domain Services Elevation of Privilege Vulnerability
Summary dbcve.org
CVE-2022-26923 is an elevation of privilege vulnerability in Active Directory Domain Services that allows an authenticated attacker to escalate privileges to Domain Admin by manipulating certificate requests in Active Directory Certificate Services (AD CS). The vulnerability exploits how AD CS handles certificate requests and allows impersonation of privileged users through crafted certificate submissions.
Mitigation
Apply the Microsoft security update released in May 2022 (KB5014697 and related patches) to all affected domain controllers. Additionally, implement certificate enrollment restrictions and monitor for suspicious certificate requests.
Weakness (CWE)
CWE-295
Improper Certificate Validation
EPSS Score
83.5%
Probability of exploitation in next 30 days
99.7th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26923
Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26923
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26923
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.