Impact
Improper certificate validation in Windows Active Directory allows an authorized local attacker to elevate privileges on the same machine. The flaw arises from the system failing to properly validate certificates during AD authentication, effectively bypassing normal trust checks. As a result, a local attacker who already has an authorized account can gain administrative rights without compromising higher‑level credentials, potentially enabling further malicious actions on the domain controller or member servers.
Affected Systems
Microsoft Windows 10 version 1607 and 1809, Microsoft Windows Server 2016 (including Server Core), Microsoft Windows Server 2019 (including Server Core), Microsoft Windows Server 2022, and Microsoft Windows Server 2025 (including Server Core). All listed operating systems running Active Directory Domain Services are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability that can be exploited to gain privileges locally. The EPSS score of less than 1% suggests that, so far, the likelihood of widespread exploitation is very low. The flaw is locally exploitable, requiring the attacker to possess an authorized local account on a domain‑joined machine; remote exploitation has not been documented. The vulnerability is not listed in the CISA KEV catalog, implying no large‑scale, active exploitation campaigns are currently reported.
OpenCVE Enrichment