Executive brief
Active Directory Certificate Services (AD CS) is a critical Windows component used to manage digital certificates across enterprise networks. A flaw in output encoding allows an authenticated attacker with appropriate permissions to escalate their privileges to higher levels within the system, potentially gaining access to sensitive certificate operations and administrative functions.
Technical details
The vulnerability stems from improper encoding or escaping of output in Active Directory Certificate Services. An authorized attacker can exploit this to escalate privileges locally on a system where AD CS is installed. The attack requires existing authorization/access to the AD CS service or environment. The vulnerability allows privilege elevation, which could enable attackers to perform unauthorized certificate operations, access sensitive keys, or move laterally within an enterprise infrastructure. A patch has been released by Microsoft as indicated in the MSRC advisory.
Affected products
- Microsoft Windows Server <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Microsoft MSRC advisory published with security update