KEV · Actively exploited
CVE-2022-26923
CRITICAL 8.8
KEV
Active Directory Domain Services Elevation of Privilege Vulnerability
EPSS
91.60%
exploit likely
percentile 99.7%
CISA Known Exploited Vulnerability
- Added to KEV
- 2022-08-18
- Remediation deadline
- 2022-09-08
- Required action
- Apply updates per vendor instructions.
- Ransomware
- No
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Fixed in Windows Server 2022 (Server Core installation) 10.0.20348.1668 Windows Server 2022 10.0.20348.1668 Windows Server 2019 (Server Core installation) 10.0.17763.4252 Windows Server 2019 10.0.17763.4252 Windows Server 2016 (Server Core installation) 10.0.14393.5850 Windows Server 2016 10.0.14393.5850 Windows 11 21H2 · 2021-H2 10.0.22000.1817 Windows 10 21H2 · 2021-H2 10.0.19044.1706 Windows 10 21H1 · 2021-H1 10.0.19043.1706 Windows 10 20H2 · 2020-H2 10.0.19042.1706 Windows 10 1909 · 2019-09 10.0.18363.2274 Windows 10 1809 · 2018-09 10.0.17763.4252 Windows 10 1607 · 2016-07 10.0.14393.5850