ZeroHour

CVE-2022-26923

KEVmass1

Authenticated Privilege Escalation in Microsoft Active Directory Domain Services

CISA: Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

CVSS 3.1
8.8 high
EPSS
84%p100
Published
()
KEV added
AI analysis

CVE-2022-26923 is an elevation-of-privilege flaw in Microsoft Active Directory Domain Services (CWE-295, improper certificate validation), widely known as the 'sAMAccountName spoofing' issue. An attacker with ordinary domain-user credentials can create or rename a computer account so its sAMAccountName matches a domain controller's name, obtain a certificate for that account, and use the flawed certificate-to-account name mapping to authenticate as that domain controller. Successful exploitation grants the attacker Domain Admin privileges and effectively full control over the Active Directory forest. Any organization running AD DS on the affected Windows 10/11, Windows 8.1, Windows RT 8.1, or Windows Server releases is exposed until patched. The flaw was fixed in Microsoft's May 2022 Patch Tuesday updates and is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-08-18, EPSS puts its 30-day exploitation probability at 83.5% (100th percentile), no public PoC is cataloged, and ransomware use is unknown.

What to do: Apply Microsoft's May 2022 security updates (or later cumulative updates) to every domain controller and affected Windows/Windows Server host, prioritizing domain controllers, and verify patch status fleet-wide. Until patched, audit recently created or renamed computer accounts whose sAMAccountName matches a domain controller name, restrict which users can add machine accounts, and monitor for unusual certificate-based logons by privileged accounts. Patching is required for U.S. federal agencies since the flaw is in CISA's KEV catalog (required action: apply updates per vendor instructions).

Affected
Microsoft Active Directory Domain Services (CISA: Microsoft Active Directory)AD DS on supported Windows and Windows Server releases
Microsoft Windows 101507, 1607, 1809, 1909, 20H2, 21H1, 21H2
Microsoft Windows 1121H2
Microsoft Windows 8.1all supported versions
Microsoft Windows RT 8.1all supported versions
Microsoft Windows Server 2012all supported editions
Microsoft Windows Server 2016all supported editions
Estimated exposure
massmillions of domain-joined systems across effectively all enterprise AD forests that had not yet applied the May 2022 updates — Active Directory is the default identity platform for Windows corporate networks and is deployed by the overwhelming majority of enterprises and government organizations, so essentially every unpatched domain (pre-May 2022 Patch Tuesday)…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Active Directory Domain Services Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Active Directory
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows 8.1, windows rt 8.1, windows server 2012, windows server 2016
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news