9
CVE-2022-26923
- EPSS 91.99%
- Veröffentlicht 10.05.2022 21:15:10
- Zuletzt bearbeitet 24.02.2025 15:48:42
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
Active Directory Domain Services Elevation of Privilege Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1507 Version < 10.0.10240.19297
Microsoft ≫ Windows 10 1607 Version < 10.0.14393.5850
Microsoft ≫ Windows 10 1809 Version < 10.0.17763.4252
Microsoft ≫ Windows 10 1909 Version < 10.0.18363.2274
Microsoft ≫ Windows 10 20h2 Version < 10.0.19042.1706
Microsoft ≫ Windows 10 21h1 Version < 10.0.19043.1706
Microsoft ≫ Windows 10 21h2 Version < 10.0.19044.1706
Microsoft ≫ Windows 11 21h2 Version < 10.0.22000.1817
Microsoft ≫ Windows 8.1 Version-
Microsoft ≫ Windows Rt 8.1 Version-
Microsoft ≫ Windows Server 2012 Versionr2
Microsoft ≫ Windows Server 2016 Version < 10.0.14393.5850
Microsoft ≫ Windows Server 2019 Version < 10.0.17763.4252
Microsoft ≫ Windows Server 2022 Version < 10.0.20348.1668
18.08.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
SchwachstelleAn authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.
BeschreibungApply updates per vendor instructions.
Erforderliche MaßnahmenTyp | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 91.99% | 0.997 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
secure@microsoft.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.