Executive brief
Active Directory Certificate Services (AD CS) is Microsoft's infrastructure for issuing digital certificates used to authenticate users, computers, and services in enterprise networks. An incomplete validation of user inputs allows an authorized attacker to manipulate certificate issuance processes over the network, potentially issuing unauthorized certificates or compromising the integrity of the certificate infrastructure.
Technical details
This vulnerability exists in Active Directory Certificate Services due to an incomplete list of disallowed inputs, resulting in insufficient input validation. The flaw allows an authorized attacker to bypass input sanitization checks and perform tampering operations over the network. The attack requires authentication to the AD CS service. Successful exploitation could lead to unauthorized certificate issuance or modification of certificate properties. A patch is expected to be available through Microsoft's regular security update process.
Affected products
- Microsoft Active Directory Certificate Services
Timeline
- 2026-09-08: disclosed