Impact
An attacker with authorized local access can exploit the improper encoding or escaping of output in Active Directory Certificate Services to gain higher privileges on the same machine. The flaw is identified as CWE‑116 and allows local privilege escalation, giving the attacker the ability to modify system or certificate service settings.
Affected Systems
The vulnerability impacts Microsoft Windows 10 versions 1607 and 1809, and all supported Windows Server releases from 2012 through 2025, including Server Core installs. Any host running AD CS on these platforms without the relevant security update is at risk.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity local privilege escalation. EPSS is not available, and the vulnerability is not listed in CISA KEV, suggesting limited or no public exploitation at this time. The attack requires local or privileged access to the target machine, so an attacker who has already compromised a workstation or domain controller can elevate to SYSTEM or similar privileges, potentially moving laterally or tampering with certificate issuance.
OpenCVE Enrichment