References https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26923 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26923 https://nvd.nist.gov/vuln/detail/cve-2022-26923 https://research.ifcr.dk/certifried-active-directory-domain-privilege-escalation-cve-2022-26923-9e098fe298f4 https://www.hackthebox.com/blog/cve-2022-26923-certifried-explained https://www.sentinelone.com/vulnerability-database/cve-2022-26923/ https://www.secrss.com/articles/42413 https://whoamianony.top/posts/certifried-active-directory-domain-privilege-escalation/ https://cloud.tencent.com/developer/article/2013603 https://www.ithome.com.tw/pr/150983 https://zhuanlan.zhihu.com/p/513935779 https://developer.volcengine.com/articles/7381553381971591205 https://www.cnblogs.com/kqdssheng/p/18916959 https://medium.com/cycraft/%E7%B2%BE%E9%81%B8%E5%A8%81%E8%84%85%E6%83%85%E8%B3%87-%E6%BC%8F%E6%B4%9E%E8%AD%A6%E8%A8%8A-ad-%E7%B6%B2%E5%9F%9F%E6%9C%8D%E5%8B%99%E6%8F%90%E6%AC%8A%E6%BC%8F%E6%B4%9E-cve-2022-26923-c535f3928661 https://nic.zjtu.edu.cn/content/aqjs/202205/1930.html https://www.51cto.com/article/711525.html https://www.cycraft.com/post/active-directory20220707 https://www.venustech.com.cn/new_type/aqtg/20220517/23870.html https://www.sxxdckj.com/cms/a/Microsoft-Windows-Active-Directory-quan-xian-ti-sheng-lou-dong-CNVD-2022-36664.html https://blog.csdn.net/m0_46377671/article/details/124951879 https://tttang.com/archive/1613/ https://bbs.kanxue.com/article-18725.htm https://qkl.seebug.org/vuldb/ssvid-99510 https://www.tenablecloud.cn/plugins/nessus/160931 https://www.huaweicloud.com/notice/2022/20220513110639487.html https://xxzx.xsyu.edu.cn/info/1010/2462.htm https://www.semperis.com/blog/ad-vulnerability-cve-2022-26923/ https://www.silverfort.com/blog/silverfort-proactively-detects-protects-against-certifried-attacks/ https://unit42.paloaltonetworks.com/microsoft-cve-2022-26925-etc/ https://www.extrahop.com/resources/detections/cve-2022-26923-active-directory-domain-services-exploit-attempt https://github.com/rayngnpc/CVE-2022-26923-rayng https://www.rapid7.com/db/vulnerabilities/msft-cve-2022-26923/ https://kudelskisecurity.com/research/active-directory-domain-services-elevation-of-privilege-vulnerability https://www.esentire.com/security-advisories/cve-2022-26923-active-directory-domain-services-elevation-of-privilege-vulnerability https://arcticwolf.com/resources/blog/poc-exploit-for-active-directory-certificate-services-vulnerability-cve-2022-26923-creates-path-to-domain-admin/ https://juggernaut-sec.com/cve-2022-26923-certifried/ https://sploitus.com/exploit?id=PACKETSTORM:180778 https://www.ibm.com/think/x-force/attacker-exploits-vulnerability-in-active-directory-certificate-services https://socprime.com/blog/cve-2022-26923-detection-active-directory-domain-privilege-escalation-vulnerability/ https://attackerkb.com/topics/iigmLeSKp1/cve-2022-26923-aka-certifried https://www.thezdi.com/blog/2024/7/31/breaking-barriers-and-assumptions-techniques-for-privilege-escalation-on-windows-part-3 https://www.ithome.com.tw/pr/150983 https://www.secrss.com/articles/42413 https://www.sentinelone.com/vulnerability-database/cve-2022-26923/
Related VulnerabilitiesPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)Windows截图工具NTLM信息泄露漏洞(CVE-2026-33829)Gradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)Windows Shell Link 敏感信息泄露与欺骗漏洞(CVE-2026-25185)PoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCsharepoint-lists-api-disclosure: Microsoft SharePoint - List API DisclosurePoCCVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows - Log File ExposurePoCsharepoint-layouts-disclosure: Microsoft SharePoint - Layouts DisclosurePoCsharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page Disclosure