CVE-2022-26923General(microsoft / windows_10_1507)

LOWCVSS 8.8 · HIGHCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Active Directory Domain Services Elevation of Privilege Vulnerability

2.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-09-08. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_1909

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Peaked 5d ago at 1 mentions (2026-03-12); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_1909windows_10_20h2windows_10_21h1windows_10_21h2windows_11_21h2windows_8.1windows_rt_8.1

2 versions affected across 14 products

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-03-12: 1Mentions · 2026-03-19: 1Mentions · 2026-03-31: 1Mentions · 2026-05-12: 1Mentions · 2026-05-15: 1Mentions · 2026-07-29: 1PoC Mentioned / Linked · 2026-03-12: 1PoC Mentioned / Linked · 2026-03-31: 1Patch / Workaround · 2026-07-29: 1Technical Details · 2026-05-12: 1Technical Details · 2026-07-29: 103-1203-1903-3105-1205-1507-29
Signal classification3 categories
General
350.0%
PoC
233.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-121
PoC1
2026-03-191
General1
2026-03-311
PoC1
2026-05-121
General1
2026-05-151
General1
2026-07-291
Patch1
Full discourse6 posts
  • سلطان (ThatYonko سابقًا)@CalledSTRIKER
    PoC

    I just completed CVE-2022-26923 room on TryHackMe! Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services. https://tryhackme.com/room/cve202226923?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=65d61286c9ae6ae3b66e1842 #tryhackme

    Post summary

    The tweet announces completing a TryHackMe room that offers a walkthrough of exploiting CVE-2022-26923 in AD Certificate Services, serving as a proof‑of‑concept demonstration.

    00020286
    2.8K followersView on X
  • Jonas Vestberg@bugch3ck
    Patch

    @0xMaz Yes it was a fix for Certifried (@ly4k_), not ESC1. https://research.ifcr.dk/certifried-active-directory-domain-privilege-escalation-cve-2022-26923-9e098fe298f4

    Post summary

    The tweet confirms that CVE‑2022‑26923, an Active Directory domain privilege‑escalation vulnerability, was fixed—no evidence of active exploitation or PoC is provided, and no false‑positive claim is made.

    0000176
    1.9K followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The text presents a raw list of CVE identifiers without any context, details, or actionable information.

    10000106
    15 followersView on X
  • ThreadLinqs@threadlinqs
    General

    NEW THREAT INTEL: AD CS ESC1 & Shadow Credentials (CVE-2022-26923) - APT28 & Fog Ransomware. 9 detections, 22 IOCs. https://intel.threadlinqs.com/#TL-2026-0497 #ThreatIntel #CyberSec #ADCS #APT28 https://t.co/n22GyiZIFt

    Post summary

    The tweet announces threat intelligence with 9 detections and 22 IOCs for CVE‑2022‑26923, but no PoC, exploit code, or patch details are provided.

    0100083
    47 followersView on X
  • Sun4lower@LittleSun4lower
    PoC

    I just completed CVE-2022-26923 room on TryHackMe! Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services. https://tryhackme.com/room/cve202226923?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #ConsistencyWins #Learning

    Post summary

    A TryHackMe walkthrough room demonstrates exploitation of CVE-2022-26923 in AD Certificate Services, offering a Proof of Concept but no detailed code or real‑world activity.

    0000029
    5 followersView on X
  • Napa County Corruption 🕵@NapaCorruption
    General

    I just completed CVE-2022-26923 room on TryHackMe! Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services. https://tryhackme.com/room/cve202226923?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=63d417a8e9eef70044a768b6 #tryhackme via @tryhackme

    Post summary

    The tweet announces a completed TryHackMe walkthrough for CVE‑2022‑26923, which is a training resource but provides no technical details, PoC, or exploit code.

    0000073
    938 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_1909---
OSmicrosoftwindows_10_20h2---
OSmicrosoftwindows_10_21h1---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---

Explore more