Active Directory Certificate Services
by Microsoft
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-62818 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. | ||
| CVE-2025-27740 | Hig | 0.57 | 8.8 | 0.03 | Apr 8, 2025 | Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2022-37976 | Hig | 0.57 | 8.8 | 0.02 | Oct 11, 2022 | Active Directory Certificate Services Elevation of Privilege Vulnerability | ||
| CVE-2024-49019 | Hig | 0.51 | 7.8 | 0.02 | Nov 12, 2024 | Active Directory Certificate Services Elevation of Privilege Vulnerability | ||
| CVE-2022-37978 | Hig | 0.49 | 7.5 | 0.01 | Oct 11, 2022 | Windows Active Directory Certificate Services Security Feature Bypass | ||
| CVE-2023-35350 | Hig | 0.47 | 7.2 | 0.01 | Jul 11, 2023 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | ||
| CVE-2023-35351 | Med | 0.43 | 6.6 | 0.01 | Jul 11, 2023 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | ||
| CVE-2025-29968 | Med | 0.42 | 6.5 | 0.02 | May 13, 2025 | Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network. | ||
| CVE-2026-54121 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2011-1264 | 0.00 | — | 0.05 | Jun 16, 2011 | Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka… |
- risk 0.57cvss 8.8epss 0.01
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.03
Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.02
Active Directory Certificate Services Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
Active Directory Certificate Services Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Active Directory Certificate Services Security Feature Bypass
- risk 0.47cvss 7.2epss 0.01
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
- risk 0.42cvss 6.5epss 0.02
Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.
- risk 0.00cvss 8.8epss 0.01
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
- CVE-2011-1264Jun 16, 2011risk 0.00cvss —epss 0.05
Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka…