Impact
Improper authorization in Active Directory Certificate Services permits an authenticated user to elevate their privileges over a network. The flaw enables a malicious actor who already has access to the domain to acquire higher permissions, potentially compromising domain control and sensitive resources. This weakness is classified as CWE-285, reflecting a failure to enforce appropriate authorization checks.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607 and 1809, Windows Server 2012 and 2012 R2, Windows Server 2016, 2019, 2022, and 2025, including both full and Server Core installations. No specific build or patch level is indicated; all listed releases may lack the fix.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of 1% suggests a low probability of exploitation at the present time. The flaw is not listed in the CISA KEV catalog. Exploitation requires an authenticated attacker who can reach AD CS over the network; a compromised account can use the flaw to gain elevated rights. While the likelihood of exploitation is currently low, administrators should still address the vulnerability promptly to prevent potential domain compromise.
OpenCVE Enrichment