9

CVE-2022-26923

Warning

Active Directory Domain Services Elevation of Privilege Vulnerability

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 10 1507 Version < 10.0.10240.19297
MicrosoftWindows 10 1607 Version < 10.0.14393.5850
MicrosoftWindows 10 1809 Version < 10.0.17763.4252
MicrosoftWindows 10 1909 Version < 10.0.18363.2274
MicrosoftWindows 10 20h2 Version < 10.0.19042.1706
MicrosoftWindows 10 21h1 Version < 10.0.19043.1706
MicrosoftWindows 10 21h2 Version < 10.0.19044.1706
MicrosoftWindows 11 21h2 Version < 10.0.22000.1817
MicrosoftWindows 8.1 Version-
MicrosoftWindows Rt 8.1 Version-
MicrosoftWindows Server 2016 Version < 10.0.14393.5850
MicrosoftWindows Server 2019 Version < 10.0.17763.4252
MicrosoftWindows Server 2022 Version < 10.0.20348.1668

18.08.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Vulnerability

An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 91.99% 0.997
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
secure@microsoft.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.