# Certifried, AD CS certificate mapping privilege escalation

Source: https://startwithidentity.com/cves/cve-2022-26923/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

CVE-2022-26923 ("Certifried") lets a low-priv user obtain a certificate that AD will map to a more privileged computer or user account. Microsoft patched it in 2022 and later shipped strong certificate mapping (KB5014754). Rapid7 and Unit 42 still report it in 2025 incident response. CVSS 8.8.

## Why it matters

This is the historical CVE we keep in a 2025-2026 identity catalog because the *control* is still missing in a lot of forests. The patch without enforcement mode is how Certifried stays a live path next to [ESC15](https://startwithidentity.com/cves/cve-2024-49019/) and [PKINIT](https://startwithidentity.com/cves/cve-2025-26647/).

## What to do

- Confirm KB5014754 is in *enforcement*, not compatibility.
- Hunt for certificate logons whose SAN does not match the account they mapped to.
- Treat AD CS as tier-zero. The CA, the templates, and the NTAuth store belong on the same review as Domain Admins.

## After you patch

Active Directory compromise is not contained by patching, because the artifacts an attacker creates outlive the vulnerability.

- **Rotate the krbtgt account twice**, with the replication interval between rotations, if there is any indication of ticket forgery. One rotation is not enough.
- **Audit AD CS certificate templates** for enrolment and enrollee-supplied-subject permissions, which are the most common escalation path left behind. See [certificate lifecycle](https://startwithidentity.com/glossary/certificate-lifecycle/).
- **Review privileged group membership and delegation rights** (Domain Admins, DnsAdmins, constrained and resource-based constrained delegation) for changes during the window.
- **Hunt for tickets with anomalous lifetimes or encryption types**, and for authentications to services that identity never touches.
- **Treat any issued certificate as a durable credential**: revoking a user's password does not revoke a certificate that authenticates as them. See [privilege escalation](https://startwithidentity.com/glossary/privilege-escalation/) and [lateral movement](https://startwithidentity.com/glossary/lateral-movement/).

## Sources

- [NVD: CVE-2022-26923](https://nvd.nist.gov/vuln/detail/CVE-2022-26923)
- Microsoft KB5014754, strong certificate mapping
