← back
CVE-2024-49019highCWE-1390

Active Directory Certificate Services Elevation of Privilege Vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.8epss 2.0%
exploitation probability
2.0%top 20% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in Windows Active Directory Certificate Services allows an authenticated user to gain higher privileges on the system. An attacker who already has access to a user account can exploit this to obtain administrative rights.

Technical detail

An elevation of privilege vulnerability exists in AD CS where an authenticated attacker can bypass access controls through improper privilege validation. The attack requires valid credentials and affects the certificate issuance process, potentially granting SYSTEM-level privileges.

Summary generated and translated by AI from the official description.
Active Directory Certificate Services Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C