CVE-2022-26923
published 2022-05-10CVE-2022-26923: Active Directory Domain Services Elevation of Privilege Vulnerability
PriorityP195high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-09-08
Exploited in the wild
EPSS
83.28%
99.6th percentile
Active Directory Domain Services Elevation of Privilege Vulnerability
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19297 | 10.0.10240.19297 |
| microsoft | windows_10_1607 | < 10.0.14393.5850 | 10.0.14393.5850 |
| microsoft | windows_10_1809 | < 10.0.17763.4252 | 10.0.17763.4252 |
| microsoft | windows_10_1909 | < 10.0.18363.2274 | 10.0.18363.2274 |
| microsoft | windows_10_20h2 | < 10.0.19042.1706 | 10.0.19042.1706 |
| microsoft | windows_10_21h1 | < 10.0.19043.1706 | 10.0.19043.1706 |
| microsoft | windows_10_21h2 | < 10.0.19044.1706 | 10.0.19044.1706 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19297 | 10.0.10240.19297 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5850 | 10.0.14393.5850 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.4252 | 10.0.17763.4252 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.4252 | 10.0.17763.4252 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2274 | 10.0.18363.2274 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1706 | 10.0.19042.1706 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1706 | 10.0.19043.1706 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19043.1706 | 10.0.19043.1706 |
| microsoft | windows_11_21h2 | < 10.0.22000.1817 | 10.0.22000.1817 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1817 | 10.0.22000.1817 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20371 | 6.3.9600.20371 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20919 | 6.3.9600.20919 |
| microsoft | windows_server_2016 | < 10.0.14393.5850 | 10.0.14393.5850 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5850 | 10.0.14393.5850 |
| microsoft | windows_server_2019 | < 10.0.17763.4252 | 10.0.17763.4252 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.4252 | 10.0.17763.4252 |
| microsoft | windows_server_2022 | < 10.0.20348.1668 | 10.0.20348.1668 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect low-privileged users manipulating the dNSHostName attribute on computer accounts they own/manage to spoof a domain controller identity before requesting an AD CS certificate. ↗
- →Monitor for certificate requests where the KDC processes certificate-based authentication without accounting for a trailing dollar sign ($) in the machine name, enabling certificate spoofing. ↗
- →Detect use of Certify or Certipy tools enumerating certificate templates and submitting certificate requests impersonating high-privileged accounts (ESC1 attack path). ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
cisa·2022-08-18·CVSS 8.8
CVE-2022-26923 [HIGH] CWE-295 Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
Vulnerability: Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
Affected: Microsoft Active Directory
An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.
Required Action: Apply updates per vendor instructions.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-26923; https://nvd.nist.gov/vuln/detail/CVE-2022-26923
Remediation Due Date: 2022-09-08
Microsoft
Active Directory Domain Services Elevation of Privilege Vulnerability
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-26923 [HIGH] Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow elevation of privilege to System.
FAQ: Where can I find out more information about this vulnerability?
Please see Certificate-based authentication changes on Windows domain controllers for more information and ways to protect yourself.
Windows Active Directory: Windows Active Directory
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release
GHSA
GHSA-j9xf-76vv-4wcg: Active Directory Domain Services Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-11
CVE-2022-26923 [HIGH] CWE-295 GHSA-j9xf-76vv-4wcg: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability.
VulnCheck
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
vulncheck·2022·CVSS 8.8
CVE-2022-26923 [HIGH] CWE-295 Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.
Affected: Microsoft Active Directory
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.group-ib.com/resources/research-hub/hi-tech-crime-trends-2022/; https://www.ibm.com/downloads/cas/L0GKXDWJ; https://www.rapid7.com/blog/post/2024/08/12/ongoing-social-engineering-campaign-refreshes-payloads/
Exploit PoC: https://vulncheck.com/xdb/f701
Sigma
Certificate Use With No Strong Mapping
sigma·CVSS 8.8
CVE-2022-34691 [HIGH] Certificate Use With No Strong Mapping
Certificate Use With No Strong Mapping
Detects a user certificate that was valid but could not be mapped to a user in a strong way (such as via explicit mapping, key trust mapping, or a SID)
This could be a sign of exploitation of the elevation of privilege vulnerabilities (CVE-2022-34691, CVE-2022-26931, CVE-2022-26923) that can occur when the KDC allows certificate spoofing by not requiring a strong mapping.
Events where the AccountName and CN of the Subject do not match, or where the CN ends in a dollar sign indicating a machine, may indicate certificate spoofing.
Detection:
condition: selection
selection:
EventID:
- 39
- 41
Provider_Name:
- Kerberos-Key-Distribution-Center
- Microsoft-Windows-Kerberos-Key-Distribution-Center
Log Source: product: windows
service: system
Elastic
Remote Computer Account DnsHostName Update
elastic_rules·CVSS 8.8
CVE-2022-26923 [HIGH] Remote Computer Account DnsHostName Update
Remote Computer Account DnsHostName Update
Identifies the remote update to a computer account's DnsHostName attribute. If the new value set is a valid domain
controller DNS hostname and the subject computer name is not a domain controller, then it's highly likely a preparation
step to exploit CVE-2022-26923 in an attempt to elevate privileges from a standard domain user to domain admin
privileges.
Query:
iam where host.os.type == "windows" and event.action == "changed-computer-account" and
user.id : ("S-1-5-21-*", "S-1-12-1-*") and
/* if DnsHostName value equal a DC DNS hostname then it's highly suspicious */
winlog.event_data.DnsHostName : "??*" and
/* exclude FPs where DnsHostName starts with the ComputerName that was changed */
not startswith~(winlog.event_data.DnsHostName, substri
Unit42
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
blogs_unit42·2026-05-11
CVE-2022-26923 Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
## Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
Stav Setty
Tom Fakterman
Shachar Roitman
Published: May 11, 2026
Malware
Threat Research
Active Directory
AD CS attacks
Certificate template
Certipy
ESC1
Fighting Ursa
Microsoft
PKI
Shadow credentials
## Executive Summary
Active Directory Certificate Services (AD CS) is a foundational component of Windows enterprise infrastructure, responsible for managing public key infrastructure (PKI) and issuing certificates that enable authentication and encryption across networks. Despite its critical role in the enterprise identity infrastructure, AD CS is often undermined by insecure default configurations and design complexities, resulting in exploitable attack surfaces. Due to misconfigured templates an
Huntress
dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025
blogs_huntress·2026-05-04
CVE-2025-53779 dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025
TL;DR: This companion blog, created in partnership with security researchers at Akamai, unpacks dMSA Ouroboros, a self-sustaining credential extraction technique in Windows Server 2025. After you read their blog , come back here for what it means in practice: a user with CreateChild on any OU or container and WriteProperty on a target account can create a dMSA that extracts the target's NT hash, persists through password rotation, survives the original attacker's account deletion, and locks out Domain Admins from remediation. Six commands. Fully patched Windows Server 2025.
## Introduction
Windows Server 2025 introduced delegated Managed Service Accounts (dMSAs) with a redesigned security model that removes the password retrieval primitive and replaces it with a KDC-mediated authorizatio
Sentinelone
CVE-2022-26923 | What is it and How to Mitigate?
blogs_sentinelone·2023-01-23·CVSS 8.8
CVE-2022-26923 [HIGH] CVE-2022-26923 | What is it and How to Mitigate?
Microsoft released a Windows security update in May 2022, disclosing CVE-2022-26923 Active Directory Domain Services Elevation of privilege vulnerability. The CVE-2022-26923 allows a lower privileged user to acquire a certificate from Active Directory Certificate Services (AD CS) and escalate privileges to the domain controller. However, issues with the update may have prevented some organizations from updating at the time, while others may have been unable to update due to local dependency or compatibility reasons.
In this post, we discuss AD CS misconfigurations that allow attackers to exploit this flaw and describe how security teams can mitigate this vulnerability .
## What Is CVE-2022-26923?
According to Microsoft’s advisory , CVE-2022-26923 is one of three CVEs relating to an elev
Sentinelone
CVE-2022-26923 | What is it and How to Mitigate?
blogs_sentinelone·2023-01-23·CVSS 8.8
CVE-2022-26923 [HIGH] CVE-2022-26923 | What is it and How to Mitigate?
Microsoft released a Windows security update in May 2022, disclosing CVE-2022-26923 Active Directory Domain Services Elevation of privilege vulnerability. The CVE-2022-26923 allows a lower privileged user to acquire a certificate from Active Directory Certificate Services (AD CS) and escalate privileges to the domain controller. However, issues with the update may have prevented some organizations from updating at the time, while others may have been unable to update due to local dependency or compatibility reasons.
In this post, we discuss AD CS misconfigurations that allow attackers to exploit this flaw and describe how security teams can mitigate this vulnerability.
## What Is CVE-2022-26923?
According to Microsoft’s advisory, CVE-2022-26923 is one of three CVEs relating to an elevat
Tenable
White Paper: Eliminating Attack Paths in Active Directory: A closer look at preventing privilege escalations
blogs_tenable·2022-11-23·CVSS 8.8
[HIGH] White Paper: Eliminating Attack Paths in Active Directory: A closer look at preventing privilege escalations
White paper
## Eliminating Attack Paths in Active Directory: A closer look at preventing privilege escalations
Knowing that you have been attacked is essential, but anticipating and preventing attacks is crucial to staying resilient and thwarting attacks.
Active Directory is a 22-year-old technology that is subject to frequent changes and has now saddled CIOs with decades of technical debt. It has many moving parts that attackers can exploit and sophisticated AD attacks rely on multiple attack paths. In many cases, attackers look to take advantage of unpatched vulnerabilities and misconfigurations in AD to elevate their privileges and gain wide-reaching access to critical enterprise assets.
Detecting and eliminating attack pathways gives enterprises the ability to block new threats bef
Sentinelone
What is Conditional Access? - A Comprehensive Guide 101
blogs_sentinelone·2022-11-23
What is Conditional Access? - A Comprehensive Guide 101
With the rapid change in modern technologies, workforces are increasingly mobile and require direct access to applications across hybrid IT environments. They often access both on-premises and cloud applications from various devices and locations, some of which could be using public or unencrypted networks. At the same time, security teams have realized that the directory service widely used to manage the required identity-related services, Active Directory , is vulnerable, and identifying its loopholes to protect it from various attacks is a considerable challenge.
How can organizations detect and block identity-related attacks before adversaries or malicious insiders establish complete Active Directory Domain Controller (DC) dominance? How can they most effectively protect critical asse
Unit42
Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
blogs_unit42·2022-07-27·CVSS 9.8
CVE-2022-26809 [CRITICAL] Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
Chao Lei
Tao Yan
Haozhe Zhang
Qi Deng
Published: July 27, 2022
High Profile Threats
Vulnerabilities
CVE-2022-26809
CVE-2022-26923
CVE-2022-26925
Microsoft
Microsoft Windows
## Executive Summary
Microsoft introduced patches for several critical vulnerabilities in their April and May 2022 security updates, including the following vulnerabilities:
CVE-2022-26809 : An unauthorized attacker can exploit this vulnerability by sending a specially crafted Remote Procedure Call (RPC) to remotely execute arbitrary code on the vulnerable device.
CVE-2022-26923 : A low-privileged user can escalate privilege to a domain ad
Unit42
Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
blogs_unit42·2022-07-27·CVSS 9.8
CVE-2022-26925 [CRITICAL] Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
## Executive Summary
Microsoft introduced patches for several critical vulnerabilities in their April and May 2022 security updates, including the following vulnerabilities:
- CVE-2022-26809: An unauthorized attacker can exploit this vulnerability by sending a specially crafted Remote Procedure Call (RPC) to remotely execute arbitrary code on the vulnerable device.
- CVE-2022-26923: A low-privileged user can escalate privilege to a domain administrator in a default Active Directory environment with the “Active Directory Certificate Services” server role installed.
- CVE-2022-26925: Unauthenticated attackers can remotely exploit and force domain controllers to authenticate them via the Windows NT LAN Manager (NTLM) security protocol.
We highly recommend that customers apply these securit
Talos
Microsoft Patch Tuesday for May 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-05-10·CVSS 8.1
[HIGH] Microsoft Patch Tuesday for May 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for May 2022 — Snort rules and prominent vulnerabilities
Microsoft returned to its normal monthly patching volume in May, disclosing and fixing 74 vulnerabilities as part of the company’s latest security update. This month’s Patch Tuesday includes seven critical vulnerabilities after Microsoft disclosed more than 140 security issues in April .
The point-to-point tunneling feature in Windows contains two of the most serious vulnerabilities that could allow an attacker to execute remote code on a targeted RAS server machine. While CVE-2022-21972 and CVE-2022-23270 are rated “critical,” Microsoft stated the attack complexity is high since an adversary needs to win a race condition, making it less likely an attacker could exploit these issues.
CVE-2022-26931 and C
Qualys
May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical.
blogs_qualys·2022-05-10·CVSS 5.6
[MEDIUM] May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
Notable Microsoft Vulnerabilities Patched
Microsoft Last But Not Least
Notable Adobe Vulnerabilities Patched
About Qualys Patch Tuesday
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response with Patch Management (PM)
Qualys Monthly Webinar Series
Join the webinar this Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 75 vulnerabilities in the May 2022 update, including one advisory ( ADV220001 ) for Azure in response to CVE-2022-29972 , a publicly exposed Zero-Day Remote Code Execution (RCE) Vulnerability, and eight vulnerabilities classified as critical as they allow Remote Code Execution (RCE) or Elevation of Privileges. This month
Qualys
May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical. | Qualys
blogs_qualys·2022-05-10·CVSS 5.6
[MEDIUM] May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- Notable Microsoft Vulnerabilities Patched
- Microsoft Last But Not Least
- Notable Adobe Vulnerabilities Patched
- About Qualys Patch Tuesday
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response with Patch Management (PM)
- Qualys Monthly Webinar Series
- Join the webinar this Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 75 vulnerabilities in the May 2022 update, including one advisory ( ADV220001 ) for Azure in response to CVE-2022-29972, a publicly exposed Zero-Day Remote Code Execution (RCE) Vulnerability, and eight vulnerabilities classified as critical as they allow Remote Code Execution (RCE) or Elevation of Privileges.
Talos
Microsoft Patch Tuesday for May 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-05-10·CVSS 8.1
CVE-2022-21972 [HIGH] Microsoft Patch Tuesday for May 2022 — Snort rules and prominent vulnerabilities
Microsoft returned to its normal monthly patching volume in May, disclosing and fixing 74 vulnerabilities as part of the company’s latest security update. This month’s Patch Tuesday includes seven critical vulnerabilities after Microsoft disclosed more than 140 security issues in April.
The point-to-point tunneling feature in Windows contains two of the most serious vulnerabilities that could allow an attacker to execute remote code on a targeted RAS server machine. While CVE-2022-21972 and CVE-2022-23270 are rated “critical,” Microsoft stated the attack complexity is high since an adversary needs to win a race condition, making it less likely an attacker could exploit these issues.
CVE-2022-26931 and CVE-2022-26923 are elevation of privilege vulnerabilities in Windows Kerberos and Windo
Crowdstrike
May 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
CTF
FullPwn / Certification
ctf_writeups·2022
FullPwn / Certification
Challenge Description:
A Certification Authority has declined our requests to access their data in order to identify a well known APT group. Unfortunately we do not have the jurisdiction to force them to cooperate. For this reason you are tasked with hacking their infrastructure in order to gather information.
Nmap found the following ports and includes the domain certification.htb and CFN-SVRDC01.certification.htb.
The page on port 80 is static. Nothing to see here.
On port 8000 we have something more interesting. A file browser app.
Which very nicely has default credentials of admin:admin
The global settings for filebrowser allows me to set commands to be executed on certain actions.
Actions like the ones listed below:
I used a powershell command to grab an obfuscated rever
2022-05-10
Published
2022-08-18
Added to CISA KEV
Exploited in the wild