< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-24T19:45:21+05:30

Certighost Exploit Enables Low-Privileged AD Users to Impersonate Domain Controllers

A newly disclosed vulnerability (CVE-2026-54121) in Active Directory Certificate Services allows low-privilege users to impersonate Domain Controllers by exploiting an insecure certificate enrollment fallback mechanism, enabling credential theft and privilege escalation. Microsoft has released patches, but organizations are advised to apply updates promptly due to the public exploit's availability.

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.

They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.

Read original article

*** END OF TRANSMISSION ***