ZeroHour

CVE-2026-69821

mass

Improper Output Encoding Enables Local Privilege Escalation in Microsoft AD CS

CVSS 3.1
7.8 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-69821 is an improper output encoding or escaping flaw (CWE-116) in Microsoft Active Directory Certificate Services (AD CS), the Windows Server role that issues and manages certificates in enterprise Active Directory environments. The flaw is triggered by an authorized, low-privileged attacker who already has local access to an affected system, requires no user interaction, and exploits AD CS failing to correctly encode or escape output it processes. Successful exploitation elevates the attacker's privileges locally on the affected server, with CVSS scoring high impact to confidentiality, integrity, and availability; because CA servers are trusted to issue domain-valid certificates, compromising one can be a stepping stone to broader domain compromise. Any organization running the AD CS role on Windows Server — effectively most enterprises that rely on Active Directory certificate authentication — is affected. There is no evidence of exploitation so far: no public proof-of-concept exists, the flaw is not in CISA's KEV, EPSS puts the 30-day exploitation probability at just 0.3%, and the fix shipped in Microsoft's September 2026 Patch Tuesday release.

What to do: Inventory which Windows Servers host the AD CS role, then apply Microsoft's September 2026 Patch Tuesday security updates to all of them, prioritizing enterprise/issuing CAs and any CA reachable over the network. As an interim mitigation, restrict interactive logon and other local access rights on CA servers to administrators only; since there is no public PoC, this can follow your normal patch cycle, but do not defer past your standard 2-4 week window and monitor the Microsoft advisory for updates.

Affected
Microsoft Active Directory Certificate Services (AD CS) role on Windows Server
Estimated exposure
mass≈ hundreds of thousands of Windows Server AD CS instances worldwide, with millions of domain users potentially able to exploit — AD CS is a core Windows Server role deployed in the large majority of enterprise Active Directory environments (hundreds of thousands of organizations globally), implying well over 100k CA servers and more than 1M dependent low-privileged…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper encoding or escaping of output in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-116
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1