Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-62810Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized local attacker to elevate privileges.

What this means
What could happen
A user with local access to a Windows server running AD CS could escalate their privileges to system level, potentially allowing them to compromise certificate issuance, authentication infrastructure, or other critical directory services.
Who's at risk
Windows Server administrators and IT staff managing Active Directory Certificate Services infrastructure, particularly those running Windows Server 2016, 2019, 2022, or 2025. Any organization using AD CS for internal PKI or certificate management should prioritize this patch.
How it could be exploited
An attacker with local user credentials on a Windows server running AD CS exploits a heap buffer overflow in the certificate services process to execute code with SYSTEM privileges. This requires local access and valid user credentials on the affected server.
Prerequisites
  • Local user account credentials on the affected Windows server
  • AD CS role installed and running on the server
  • No elevated privileges initially required (local user account is sufficient)
Locally exploitableLow complexity attackAffects authentication and PKI infrastructureMultiple Windows versions impacted
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/4
Do now
0/1
HARDENINGRestrict local server access to AD CS servers—limit who can log in locally to only administrators and service accounts that require it
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the September 2026 Windows security update to all AD CS servers (Windows Server 2016, 2019, 2022, or 2025)
All products
HARDENINGReview and audit local user accounts on all AD CS servers, removing any unnecessary or dormant accounts
Long-term hardening
0/1
HARDENINGEnable Windows Defender Application Control (WDAC) or AppLocker on AD CS servers to restrict execution of unauthorized programs
API: /api/v1/advisories/b2caf2df-d7f5-4a37-a8d4-597a69ed0b74

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.