Junglewise Threat Intelligence

CVE-2022-26923: Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

CVE-2022-26923 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-08-18

Technologies: Microsoft Windows Server 2022, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2019, Microsoft Active Directory, Microsoft Windows Server 2016, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

An authenticated user can manipulate attributes on computer accounts they own or manage to acquire a certificate from Active Directory Certificate Services. This flaw allows for privilege escalation to SYSTEM by exploiting improper certificate validation in Active Directory Domain Services.

Affected products

  • Microsoft Windows 10 up to (excluding) 10.0.10240.19297
  • Microsoft Windows 11 up to (excluding) 10.0.22000.1817
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016 up to (excluding) 10.0.14393.5850
  • Microsoft Windows Server 2019 up to (excluding) 10.0.17763.4252
  • Microsoft Windows Server 2022 up to (excluding) 10.0.20348.1668

Timeline

  • 2022-08-18: disclosed
  • 2022-08-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-08-18: patched: Patch information provided by Microsoft Corporation

Related threats