CVE-2022-26923CISA KEV
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.
- Product
- Active Directory
- Added to KEV
- 18 Aug 2022
- Federal remediation due
- 8 Sep 2022
- Known ransomware use
- Not reported