CVE detail
CVE-2022-26923
Active Directory Domain Services Elevation of Privilege Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders.
vendorunit42.paloaltonetworks.comMay 11, 2026, 10:00 PMExperts linked an ongoing social engineering campaign, aimed at deploying the malware SystemBC, to the Black Basta ransomware group. Rapid7 researchers uncovered a new social engineering campaign distributing the SystemBC dropper to the Black Basta ransomware operation. On June 20, 2024, Rapid7 researchers detected multiple attacks consistent with an ongoing social engineering campaign being tracked […]
newssecurityaffairs.comAug 15, 2024, 8:40 AMThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) added 7 new flaws to its Known Exploited Vulnerabilities Catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week added seven new flaws to its Known Exploited Vulnerabilities Catalog, including a critical SAP security vulnerability tracked as CVE-2022-22536. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday […]
newssecurityaffairs.comAug 20, 2022, 4:56 PMThe US Cybersecurity and Infrastructure Security Agency (CISA) has added a critical SAP vulnerability to its Known Exploited Vulnerabilities Catalog less than one week after its details were disclosed at the Black Hat and Def Con hacker conferences.
newswww.securityweek.comAug 19, 2022, 10:17 AM- Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)Unit42
We provide an overview of CVE-2022-26809, CVE-2022-26923 and CVE-2022-26925, along with recommendations for mitigation.
vendorunit42.paloaltonetworks.comJul 27, 2022, 11:00 PM If you are as old as I am, you remember when you first had to deal with domains and Active Directory (AD). Even if you aren’t as old as I am, you still probably must deal with domains and Active Directory. If you are just starting out at a new firm, you probably know only […]
newswww.csoonline.comMay 25, 2022, 9:00 AM- Microsoft patches Windows LSA spoofing zero-day under active attack (CVE-2022-26925)Help Net Security
May 2022 Patch Tuesday is here, and Microsoft has marked it by releasing fixes for 74 CVE-numbered vulnerabilities, including one zero-day under active attack (CVE-2022-26925) and two publicly known vulnerabilities (CVE-2022-29972 and CVE-2022-22713). Vulnerabilities of particular note First and foremost, we have CVE-2022-26925, an “important” spoofing vulnerability in Windows Local Security Authority (LSA) that may turn into a “critical” one if combined with NTLM relay attacks. “Being actively exploited in the wild, this [vulnerability] allows … More →
newswww.helpnetsecurity.comMay 10, 2022, 7:10 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-26934CVSS 6.5 · Medium
Windows Graphics Component Information Disclosure Vulnerability
- CVE-2022-26925CVSS 8.1 · High
Windows LSA Spoofing Vulnerability
- CVE-2022-26904CVSS 7.0 · High
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2022-24521CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-22718CVSS 7.8 · High
Windows Print Spooler Elevation of Privilege Vulnerability
KEV listed4 mentions - CVE-2022-21999CVSS 7.8 · High
Windows Print Spooler Elevation of Privilege Vulnerability