HIGH

CVE-2022-26923

Microsoft Windows 10 1507 2022-05-10 CVSS v3.1
CVSS
8.8
KEV

Description

Active Directory Domain Services Elevation of Privilege Vulnerability

Summary dbcve.org

CVE-2022-26923 is an elevation of privilege vulnerability in Active Directory Domain Services that allows an authenticated attacker to escalate privileges to Domain Admin by manipulating certificate requests in Active Directory Certificate Services (AD CS). The vulnerability exploits how AD CS handles certificate requests and allows impersonation of privileged users through crafted certificate submissions.

Mitigation

Apply the Microsoft security update released in May 2022 (KB5014697 and related patches) to all affected domain controllers. Additionally, implement certificate enrollment restrictions and monitor for suspicious certificate requests.

Patch Commit

Weakness (CWE)

CWE-295 Improper Certificate Validation

EPSS Score

83.5%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE