Executive brief
Microsoft Active Directory Domain Services contains an elevation of privilege vulnerability. An authenticated attacker can exploit this flaw to escalate privileges within a domain environment. This vulnerability has been observed being exploited in the wild.
Affected products
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.4770
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.2300
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.350
- Microsoft Windows Server 2004 up to (excluding) 10.0.19041.1348
- Microsoft Windows Server 20H2 up to (excluding) 10.0.19042.1348
Timeline
- 2021-11-09: disclosed: NVD Published Date
- 2022-04-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-02: patched: Due date for remediation per CISA BOD 22-01