CVE-2022-26923
Active Directory Domain Services Elevation of Privilege Vulnerability
- Affected products
- Active Directory Domain Services, Windows Active Directory Certificate Services, Windows
- Microsoft Windows 10 1507
- < 10.0.10240.19297
- Microsoft Windows 10 1607
- < 10.0.14393.5850
- Microsoft Windows 10 1809
- < 10.0.17763.4252
- Microsoft Windows 10 1909
- < 10.0.18363.2274
- Microsoft Windows 10 20h2
- < 10.0.19042.1706
- Microsoft Windows 10 21h1
- < 10.0.19043.1706
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 83.0% (100th percentile)
- Weakness
- CWE-295
- NVD status
- Analyzed
- Published
- 2022-05-10
CVE-2022-26923 at NVD
8 known exploits for CVE-2022-26923
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Certificate Validation in Microsoft
Exploit for Improper Certificate Validation in Microsoft
Active Directory Certificate Services (ADCS) Privilege Escalation (Certifried)
Exploit for Improper Certificate Validation in Microsoft
Active Directory Certificate Services (ADCS) privilege escalation (Certifried)
Exploit for Improper Certificate Validation in Microsoft
Exploit for Improper Certificate Validation in Microsoft
Exploit for Improper Certificate Validation in Microsoft