Active Directory Domain Services Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-55001Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A vulnerability in Windows Active Directory Domain Services allows improper certificate validation, enabling an authorized local attacker to elevate privileges on domain-joined systems. This affects Windows 10 (versions 1607 and 1809), Windows Server 2016, 2019, 2022, and 2025. An attacker with local user credentials can escalate to elevated system or domain administrator privileges.

What this means
What could happen
An attacker with local access to a domain-joined Windows server or workstation can gain elevated privileges and take control of critical infrastructure systems. In water or electric utilities, this could allow unauthorized changes to supervisory systems, PLCs, or historian servers that manage pumps, generators, or other essential equipment.
Who's at risk
This affects all organizations running Windows servers or workstations joined to Active Directory, particularly water utilities and electric utilities using Windows-based supervisory systems, historians, or engineering workstations connected to SCADA networks. Any critical infrastructure server running Windows 10 or Windows Server (2016 through 2025) in a domain is at risk.
How it could be exploited
An attacker with local user credentials on a domain-joined machine exploits improper certificate validation in Active Directory to escalate privileges to system or domain administrator level. This gives them ability to modify configurations, disable security controls, or inject malicious commands affecting downstream SCADA/industrial control systems.
Prerequisites
  • Local user account on a Windows 10 or Windows Server system joined to an Active Directory domain
  • Active Directory Domain Services running on the network
Privilege escalation from local account to system/admin levelAffects Active Directory domain authenticationImproper certificate validationLow complexity exploitation
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 10.0.14393.9339
Remediation & Mitigation
0/7
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXApply Microsoft's July 2026 security update to all Windows Server 2019 systems
Windows Server 2022
HOTFIXApply Microsoft's July 2026 security update to all Windows Server 2022 systems
Windows Server 2025
HOTFIXApply Microsoft's July 2026 security update to all Windows Server 2025 systems
Windows Server 2016
HOTFIXApply Microsoft's July 2026 security update to all Windows 10 Version 1607 and Windows Server 2016 systems
All products
HOTFIXApply Microsoft's July 2026 security update to all Windows 10 Version 1809 systems
Long-term hardening
0/2
HARDENINGRestrict local administrative access on domain-joined servers to only personnel who require it
HARDENINGImplement privileged account management (PAM) controls to audit and limit use of domain admin credentials
API: /api/v1/advisories/3643a372-7bcb-408d-b675-ad49d017659b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.