CVE-2022-26923
CISA 기관 조치 기한: 2022-09-08
Microsoft Active Directory
An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.
KEV 필수 조치: Apply updates per vendor instructions.