🔒 Certighost (CVE-2026-54121) — AD CS Domain Controller Impersonation
Low-privileged domain user can impersonate a Domain Controller via an AD CS enrollment chase fallback. By supplying
The CA then blindly trusts the returned directory objects (
🔗 Research:
https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26
🔗 Source:
https://github.com/aniqfakhrul/CVE-2026-54121
#ad #adcs #pkinit #machineaccountquota
Low-privileged domain user can impersonate a Domain Controller via an AD CS enrollment chase fallback. By supplying
cdc (Client DC) and rmd (Remote Domain) request attributes, an attacker forces the Enterprise CA to query an attacker-controlled host over SMB and LDAP.The CA then blindly trusts the returned directory objects (
objectSid + dNSHostName of a real DC) and issues a certificate containing strong identity mapping for the Domain Controller. This allows successful PKINIT authentication as the DC.🔗 Research:
https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26
🔗 Source:
https://github.com/aniqfakhrul/CVE-2026-54121
#ad #adcs #pkinit #machineaccountquota
1🔥18❤6👍2👎1😱1