CVE-2022-26923

HIGH KEV RANSOMWARE

Active Directory Certificate Services (ADCS) privilege escalation (Certifried)

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2022-26923 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 18, 2022, with confirmed use in ransomware campaigns. EIP tracks 11 public exploits from researchers including evilashz, LudovicPatho, lsecqt, including a Metasploit module auxiliary/admin/dcerpc/cve_2022_26923_certifried.

AI-analyzed exploit summary This repository contains a vulnerability scanner for detecting common Active Directory vulnerabilities, including CVE-2022-26923 (ADCS relay attacks). The code includes modules for interacting with ADCS (Active Directory Certificate Services) and other AD-related services.

Description

Active Directory Domain Services Elevation of Privilege Vulnerability

Exploits (11)

nomisec SCANNER 79 stars
by evilashz · remote-auth
https://github.com/evilashz/PIGADVulnScanner

This repository contains a vulnerability scanner for detecting common Active Directory vulnerabilities, including CVE-2022-26923 (ADCS relay attacks). The code includes modules for interacting with ADCS (Active Directory Certificate Services) and other AD-related services.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Active Directory Certificate Services (ADCS)
Auth required
Prerequisites: Domain access · Valid credentials · Network connectivity to ADCS
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 41 stars
by LudovicPatho · poc
https://github.com/LudovicPatho/CVE-2022-26923_AD-Certificate-Services

This PoC demonstrates privilege escalation in Active Directory Certificate Services (AD CS) by manipulating the DnsHostName attribute to obtain a certificate, leading to domain administrator privileges. It uses Certipy and Impacket to exploit CVE-2022-26923.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Active Directory Certificate Services (AD CS) on Windows Server
Auth required
Prerequisites: Low-privileged AD user credentials · AD CS running on the domain · Certipy and Impacket installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 17 stars
by lsecqt · poc
https://github.com/lsecqt/CVE-2022-26923-Powershell-POC

This PoC demonstrates privilege escalation via CVE-2022-26923 by exploiting misconfigured Active Directory Certificate Services (AD CS) templates. It loads Certify and Rubeus in memory to request a certificate for an administrative user, convert it to .pfx, and generate a Kerberos ticket for privilege escalation.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Active Directory Certificate Services (AD CS) with vulnerable certificate templates
Auth required
Prerequisites: Access to a domain-joined machine · Misconfigured AD CS certificate template · Network connectivity to the attacker's server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 6 stars
by r1skkam · poc
https://github.com/r1skkam/TryHackMe-CVE-2022-26923

This repository is a writeup for CVE-2022-26923, detailing the exploitation of a vulnerability in Active Directory Certificate Services. It includes references to external resources and explanations but does not contain exploit code.

Classification
Writeup 100%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Active Directory Certificate Services
Auth required
Prerequisites: Access to Active Directory environment · Knowledge of certificate templates
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by Gh-Badr · poc
https://github.com/Gh-Badr/CVE-2022-26923

This repository provides a proof-of-concept exploit for CVE-2022-26923, a privilege escalation vulnerability in Active Directory Certificate Services (AD CS). It includes a script to set up the environment and detailed steps to exploit the vulnerability, resulting in domain administrator privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Active Directory Certificate Services (AD CS) on Windows Server 2019
Auth required
Prerequisites: Vagrant · VirtualBox · Low-privileged user credentials · Network access to the AD CS server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Nefhara · remote-auth
https://github.com/Nefhara/CVE-2022-26923

This repository contains a functional exploit script for CVE-2022-26923 (Certifried), which automates privilege escalation in Active Directory environments by abusing AD CS. It includes two methods: direct PKINIT hash extraction and a fallback using RBCD + S4U for NTLM hash dumping.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Active Directory Certificate Services (AD CS)
Auth required
Prerequisites: valid domain user credentials · access to AD CS · certipy-ad · impacket · bloodyAD · openssl
devstral-2 · analyzed May 29, 2026 Full analysis →
nomisec WRITEUP
by victorhugomierez · poc
https://github.com/victorhugomierez/CVE-2022-26923

This repository provides a detailed technical analysis of CVE-2022-26923, a privilege escalation vulnerability in Active Directory Certificate Services (AD CS). It explains the core mechanics, including computer account manipulation, SPN modification, and certificate enrollment to achieve Domain Admin privileges.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Active Directory Certificate Services (AD CS)
Auth required
Prerequisites: Low-privileged domain user access · Active Directory Certificate Services (AD CS) with vulnerable templates
devstral-2 · analyzed May 21, 2026 Full analysis →
nomisec WORKING POC
by Eliasdekiniweek · remote-auth
https://github.com/Eliasdekiniweek/CVE-2022-26923

This repository contains a functional exploit script for CVE-2022-26923 (Certifried), which abuses Active Directory Certificate Services to escalate privileges. The script automates the creation of a machine account, requests a certificate, and performs RBCD attacks to gain administrative access.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Active Directory Certificate Services (AD CS)
Auth required
Prerequisites: Valid domain credentials · Access to AD CS · Certipy and BloodyAD tools
devstral-2 · analyzed Feb 21, 2026 Full analysis →
nomisec WRITEUP
by rayngnpc · remote-auth
https://github.com/rayngnpc/CVE-2022-26923-rayng

This repository provides a detailed guide on exploiting CVE-2022-26923, a privilege escalation vulnerability in Active Directory Certificate Services (AD CS). It includes steps for setting up virtual machines, configuring networks, and executing the exploit using tools like Impacket and Certipy.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Active Directory Certificate Services (AD CS)
Auth required
Prerequisites: Vagrant · VirtualBox · Kali Linux VM · Windows Server 2022 VM · Impacket · Certipy
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by Yowise · remote-auth
https://github.com/Yowise/CVE-2022-26923

This repository provides a detailed writeup on CVE-2022-26923, a privilege escalation vulnerability in Microsoft Active Directory Certificate Services (AD CS). It explains how an attacker can exploit the Machine template to impersonate a Domain Controller by modifying the DNS Name of a newly enrolled host.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Active Directory Certificate Services (AD CS)
Auth required
Prerequisites: Access to an enrolled host in the domain · Ability to modify the DNS Name of the host · Active Directory Certificate Services (AD CS) with vulnerable Machine template
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
by Oliver Lyak, CravateRouge, Erik Wynter, Christophe De La Fuente · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/dcerpc/cve_2022_26923_certifried.rb

This Metasploit module exploits CVE-2022-26923 (Certifried) to escalate privileges in Active Directory Certificate Services (ADCS) by impersonating a Domain Controller account, requesting a certificate, and authenticating via PKINIT to obtain a TGT and TGS for privileged access.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Active Directory Certificate Services (ADCS)
Auth required
Prerequisites: Valid domain credentials with permissions to create computer accounts · SMB and LDAP access to the domain controller · ADCS configured with vulnerable certificate templates
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.9160
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-08-18
VulnCheck KEV 2022-08-18
InTheWild.io 2022-08-18
ENISA EUVD EUVD-2022-31469
Ransomware Use Confirmed
CWE
CWE-295
Status published
Products (14)
microsoft/windows_10_1507 < 10.0.10240.19297
microsoft/windows_10_1607 < 10.0.14393.5850
microsoft/windows_10_1809 < 10.0.17763.4252
microsoft/windows_10_1909 < 10.0.18363.2274
microsoft/windows_10_20h2 < 10.0.19042.1706
microsoft/windows_10_21h1 < 10.0.19043.1706
microsoft/windows_10_21h2 < 10.0.19044.1706
microsoft/windows_11_21h2 < 10.0.22000.1817
microsoft/windows_8.1
microsoft/windows_rt_8.1
... and 4 more
Published May 10, 2022
KEV Added Aug 18, 2022
Tracked Since Feb 18, 2026