Start with Identity

CVE-2022-26923Certifried, AD CS certificate mapping privilege escalation

high · CVSS 8.8
Product: Active Directory Certificate ServicesVendor: MicrosoftDisclosed: 2022-05-10Status: PatchedNVD ↗

What broke

CVE-2022-26923 ("Certifried") lets a low-priv user obtain a certificate that AD will map to a more privileged computer or user account. Microsoft patched it in 2022 and later shipped strong certificate mapping (KB5014754). Rapid7 and Unit 42 still report it in 2025 incident response. CVSS 8.8.

Why it matters

This is the historical CVE we keep in a 2025-2026 identity catalog because the control is still missing in a lot of forests. The patch without enforcement mode is how Certifried stays a live path next to ESC15 and PKINIT.

What to do

  • Confirm KB5014754 is in enforcement, not compatibility.
  • Hunt for certificate logons whose SAN does not match the account they mapped to.
  • Treat AD CS as tier-zero. The CA, the templates, and the NTAuth store belong on the same review as Domain Admins.

Sources

Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.