CVE-2022-26923: Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.
Other sources
Active Directory Domain Services Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20371Fixed in 6.3.9600.20365Patch KB5014001 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20919Patch KB5025288 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20367Patch KB5014025 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5850Patch KB5025228 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19297Patch KB5013963 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.1706Patch KB5013942 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1706Patch KB5013942 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1706Patch KB5013942 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.1817Patch KB5025224 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1668Patch KB5025230 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.2274Patch KB5013945 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4252Patch KB5025229
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26923?
CVE-2022-26923 has a high severity rating due to its potential for privilege escalation to SYSTEM level.
How do I fix CVE-2022-26923?
To fix CVE-2022-26923, apply the appropriate security updates or patches provided by Microsoft for the affected systems.
Which systems are affected by CVE-2022-26923?
CVE-2022-26923 affects various Windows operating systems, including Windows 10, Windows Server 2016, and Windows Server 2022 among others.
What type of vulnerability is CVE-2022-26923?
CVE-2022-26923 is an Active Directory Domain Services Elevation of Privilege vulnerability.
Can an authenticated user exploit CVE-2022-26923?
Yes, an authenticated user could exploit CVE-2022-26923 to manipulate attributes on computer accounts they manage.