Difference between revisions of "Enterprise Certificate Authority"

From MgmtWiki
Jump to: navigation, search
(Problems)
(Problems)
Line 10: Line 10:
 
There have been multiple vulnerabilities reported to the US Government the top three in 2022 are for Microsoft AD.
 
There have been multiple vulnerabilities reported to the US Government the top three in 2022 are for Microsoft AD.
 
* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34691 CVE-2022-34691] An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow elevation of privilege to System.
 
* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34691 CVE-2022-34691] An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow elevation of privilege to System.
* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26931 CVE-2022-26931]
+
* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26931 CVE-2022-26931] Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability.
 
* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26923 CVE-2022-26923]
 
* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26923 CVE-2022-26923]
  

Revision as of 15:50, 8 February 2023

Full Title or Meme

Any Certificate Authority that is designed to apply to people, natural or otherwise, that are known to the Enterprise.

Context

Problems

There have been multiple vulnerabilities reported to the US Government the top three in 2022 are for Microsoft AD.

  • CVE-2022-34691 An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow elevation of privilege to System.
  • CVE-2022-26931 Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability.
  • CVE-2022-26923

Solutions

References