CISA Known Exploited Vulnerability

CVE-2022-26923

Microsoft · Active Directory

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-295
Ransomware Unknown

CISA description

An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.

Required action

Apply updates per vendor instructions.