Active Directory Certificate Services Elevation of Privilege Vulnerability

Plan PatchCVSS 8.8CVE-2026-54121Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Improper authorization in Active Directory Certificate Services (AD CS) allows an authenticated attacker to elevate privileges over a network. The vulnerability affects Windows 10 (versions 1607 and 1809) and Windows Server (2016, 2019, 2022, and 2025). Exploitation is assessed as less likely but requires a security update to remediate.

What this means
What could happen
An authenticated attacker on your network could exploit this flaw to escalate from a standard user account to higher privileges on systems running AD CS, potentially gaining administrative access to your directory infrastructure and compromised endpoints.
Who's at risk
Organizations running Windows Server 2016, 2019, 2022, or 2025 with Active Directory Certificate Services enabled, as well as Windows 10 systems that are part of an Active Directory domain. This affects any utility or municipality with an internal Windows-based IT infrastructure managing domain identity and certificate services.
How it could be exploited
An attacker with valid domain credentials and network access to a Windows Server running Active Directory Certificate Services could send a specially crafted request over the network to trigger improper authorization checks. This would allow them to escalate their privilege level without requiring administrative credentials or user interaction.
Prerequisites
  • Valid domain user credentials
  • Network access to a Windows server with Active Directory Certificate Services running
  • Affected Windows Server version (2016, 2019, 2022, or 2025) or Windows 10 system in an AD environment
Remotely exploitableAuthentication required (valid domain credentials)Low complexity exploitationAffects infrastructure/directory servicesHigh CVSS score (8.8)
Exploitability
Some exploitation risk — EPSS score 1.8%
Public Proof-of-Concept (PoC) on GitHub (10 repositories)
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 10.0.14393.9339
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the July 2026 security update to all affected Windows Server and Windows 10 systems to patch the AD CS authorization vulnerability
API: /api/v1/advisories/f345606a-0293-48d6-a0a0-e6139d5f69cc

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.