Active Directory Certificate Services (AD CS) Tampering Vulnerability

MonitorCVSS 6.5CVE-2026-69624Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Incomplete validation of user input in Active Directory Certificate Services allows an authorized attacker to tamper with certificate data over the network. This could enable unauthorized certificate issuance or manipulation of certificate attributes that downstream systems rely on for authentication and trust.

What this means
What could happen
An authorized user with access to Active Directory Certificate Services could modify certificate-related data, potentially allowing them to issue unauthorized certificates or manipulate certificate validation processes that critical infrastructure systems may rely on.
Who's at risk
Water utilities and municipal electric operators running Windows Server 2016, 2019, 2022, or 2025 as domain controllers or certificate servers should prioritize this update. Any organization using AD CS for SCADA system authentication or industrial device certificate validation is at risk if an insider or compromised account has elevated AD permissions.
How it could be exploited
An attacker with valid credentials for your Active Directory environment could interact with AD CS APIs or interfaces to submit specially crafted inputs that bypass validation checks, allowing them to tamper with certificate attributes or issuance parameters.
Prerequisites
  • Valid Active Directory user credentials or service account access
  • Network access to the AD CS server (typically port 443 for web enrollment or RPC ports 135/445 for admin access)
  • Administrative or Certificate Manager roles on the AD CS server
Requires valid credentialsLow complexity exploitationAffects identity and trust infrastructurePotential to compromise SCADA/ICS device trust chains
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/8
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 and Server Core to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 and Server Core to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 and Server Core to Build 10.0.26100.33438 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 and Server Core to Build 10.0.14393.9512 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1607 (32-bit and x64) to Build 10.0.14393.9512 or later
Long-term hardening
0/2
HARDENINGRestrict network access to AD CS servers to only authorized administrative users and systems; disable web enrollment if not required
HARDENINGReview AD CS certificate manager role assignments and revoke unnecessary elevated permissions
API: /api/v1/advisories/d8d50545-35c6-4d4c-a7dc-8b5e7589d25f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.