CVE-2022-26923
KEVmass1Authenticated Privilege Escalation in Microsoft Active Directory Domain Services
CISA: Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
CVE-2022-26923 is an elevation-of-privilege flaw in Microsoft Active Directory Domain Services (CWE-295, improper certificate validation), widely known as the 'sAMAccountName spoofing' issue. An attacker with ordinary domain-user credentials can create or rename a computer account so its sAMAccountName matches a domain controller's name, obtain a certificate for that account, and use the flawed certificate-to-account name mapping to authenticate as that domain controller. Successful exploitation grants the attacker Domain Admin privileges and effectively full control over the Active Directory forest. Any organization running AD DS on the affected Windows 10/11, Windows 8.1, Windows RT 8.1, or Windows Server releases is exposed until patched. The flaw was fixed in Microsoft's May 2022 Patch Tuesday updates and is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-08-18, EPSS puts its 30-day exploitation probability at 83.5% (100th percentile), no public PoC is cataloged, and ransomware use is unknown.
What to do: Apply Microsoft's May 2022 security updates (or later cumulative updates) to every domain controller and affected Windows/Windows Server host, prioritizing domain controllers, and verify patch status fleet-wide. Until patched, audit recently created or renamed computer accounts whose sAMAccountName matches a domain controller name, restrict which users can add machine accounts, and monitor for unusual certificate-based logons by privileged accounts. Patching is required for U.S. federal agencies since the flaw is in CISA's KEV catalog (required action: apply updates per vendor instructions).
| Microsoft Active Directory Domain Services (CISA: Microsoft Active Directory) | AD DS on supported Windows and Windows Server releases |
| Microsoft Windows 10 | 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2 |
| Microsoft Windows 11 | 21H2 |
| Microsoft Windows 8.1 | all supported versions |
| Microsoft Windows RT 8.1 | all supported versions |
| Microsoft Windows Server 2012 | all supported editions |
| Microsoft Windows Server 2016 | all supported editions |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Active Directory Domain Services Elevation of Privilege Vulnerability
- Affected
- Microsoft Active Directory
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows 8.1, windows rt 8.1, windows server 2012, windows server 2016
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H