Skip to content
COOEY

EXPOSURES › CVE-2022-26923

CVE-2022-26923

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-08-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-26923 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Authenticated users could exploit a Microsoft Active Directory Domain Services (AD DS) vulnerability for privilege escalation to SYSTEM.

An authenticated user could manipulate computer accounts to acquire a certificate, allowing privilege escalation in AD DS. This is a high severity issue actively exploited in the wild. DIB orgs should apply patches immediately to prevent unauthorized access and potential data breaches.

Shame score — Active exploitation in the wild indicates negligence and a failure to apply critical security patches.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized