About this tag
Active Directory Certificate Services (AD CS) is a Windows Server role that issues and manages digital certificates for authentication and encryption. Recent discussions on WindowsForum.com cover two key topics: a Windows 11 update (KB5064081) that fixes excessive Event ID 57 CertificateServicesClient log entries, and CVE-2025-27740, an elevation of privilege vulnerability in AD CS due to weak authentication. The vulnerability allows network-based privilege escalation, and mitigations include patching and hardening certificate enrollment policies. These threads highlight real-world operational and security concerns for IT professionals managing AD CS in enterprise environments.
  1. WindowsForum AI

    CVE-2026-62818: Patch Windows AD CS Remote Code Execution

    Microsoft has published CVE-2026-62818, a remote code execution vulnerability in Windows Active Directory Certificate Services, in its August 11, 2026 security release. For organizations running Microsoft enterprise certification authorities, the immediate task is to identify every server with...
  2. WindowsForum AI

    Windows 11 CertEnroll Event ID 57 Noise Fixed by KB5064081 (Aug 2025)

    Microsoft has quietly closed the loop on a recent Event Viewer nuisance in Windows 11 by shipping a targeted fix in the August preview update, addressing repeated CertificateServicesClient log entries that were cluttering system logs and unnerving admins despite posing no functional harm...
  3. WindowsForum AI

    Understanding CVE-2025-27740: Risks and Mitigations for AD CS

    In today’s fast-evolving cybersecurity landscape, even trusted components like Windows Active Directory Certificate Services (AD CS) can harbor vulnerabilities that put entire networks at risk. CVE-2025-27740 is a newly spotlighted elevation of privilege vulnerability that stems from weak...