May 2022: Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2022-26923 Published on May 10, 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
Known Exploited Vulnerability
This Microsoft Active Directory Domain Services Privilege Escalation Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.
The following remediation steps are recommended / required by September 8, 2022: Apply updates per vendor instructions.
Weakness Type
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Products Associated with CVE-2022-26923
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Windows 10 Version 1809:- Version 10.0.17763.0 and below 10.0.17763.4252 is affected.
- Version 10.0.0 and below 10.0.17763.4252 is affected.
- Version 10.0.17763.0 and below 10.0.17763.4252 is affected.
- Version 10.0.17763.0 and below 10.0.17763.4252 is affected.
- Version 10.0.0 and below 10.0.18363.2274 is affected.
- Version 10.0.0 and below 10.0.19043.1706 is affected.
- Version 10.0.20348.0 and below 10.0.20348.1668 is affected.
- Version 10.0.0 and below 10.0.19042.1706 is affected.
- Version 10.0.0 and below 10.0.19042.1706 is affected.
- Version 10.0.0 and below 10.0.22000.1817 is affected.
- Version 10.0.19043.0 and below 10.0.19043.1706 is affected.
- Version 10.0.10240.0 and below 10.0.10240.19297 is affected.
- Version 10.0.14393.0 and below 10.0.14393.5850 is affected.
- Version 10.0.14393.0 and below 10.0.14393.5850 is affected.
- Version 10.0.14393.0 and below 10.0.14393.5850 is affected.
- Version 6.3.0 and below 6.3.9600.20371 is affected.
- Version 6.3.9600.0 and below 6.3.9600.20919 is affected.
- Version 6.3.9600.0 and below 6.3.9600.20919 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.