Executive brief
An authenticated user can manipulate attributes on computer accounts they own or manage to acquire a certificate from Active Directory Certificate Services. This flaw allows for privilege escalation to SYSTEM by exploiting improper certificate validation in Active Directory Domain Services.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.10240.19297
- Microsoft Windows 11 up to (excluding) 10.0.22000.1817
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.5850
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.4252
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.1668
Timeline
- 2022-08-18: disclosed
- 2022-08-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-08-18: patched: Patch information provided by Microsoft Corporation