{"id":1998,"date":"2026-07-24T15:31:03","date_gmt":"2026-07-24T15:31:03","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1998"},"modified":"2026-07-24T15:31:03","modified_gmt":"2026-07-24T15:31:03","slug":"certighost-exploit-lets-low-privileged-active-directory-users-impersonate-a-domain-controller","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1998","title":{"rendered":"Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 24, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Enterprise Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjdJCaF3dwhncVhtS_dn9W8CUCwJSHRmtCVTK5_fXnS6RpDI4GaVTcSVoXvmo_JgxUyd-H5G3yQaRAg3Ahp__DMlq-M5r9ejhJTdk5QlVuv16HVXDWV7e3HJAijAVBRumD3XSyeyQ1O477nfXFfTvCwgFeXlYF8QIdfTN4mlYAu28JGFN7lOWTEoKwlG9g\/s1700-e365\/certighost.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.<\/p>\n<p>They codenamed the flaw <strong>Certighost<\/strong>. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the <code>krbtgt<\/code> secret through <code>DCSync<\/code>.<\/p>\n<p>Microsoft patched the Active Directory Certificate Services (AD CS) issue ten days earlier as <strong><code>CVE-2026-54121<\/code><\/strong>. Microsoft classed the flaw as improper authorization and assigned it a CVSS score of 8.8.<\/p>\n<p>Exploitation requires network access and a domain account, but no administrator rights or user interaction. In the researchers&#8217; test, a normal <code>Domain Users<\/code> account could create a computer account under the default <code>ms-DS-MachineAccountQuota<\/code> value of <code>10<\/code> or reuse one it already controlled.<\/p>\n<p>The chain also required an Enterprise CA that followed the vulnerable chain path, enrollment through the default Machine template, and network reachability from the CA to the attacker&#8217;s SMB and LDAP listeners.<\/p>\n<p>Organizations running an Enterprise CA should install Microsoft&#8217;s July 14 updates on AD CS hosts. As of July 24, no primary source reviewed by The Hacker News reported exploitation in the wild, but the full proof-of-concept was public. That absence of reporting does not prove that exploitation has not occurred.<\/p>\n<p>The researchers also documented a lab-tested way to disable the chase fallback when immediate patching is not possible, although it can break legitimate enrollment flows.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The bug sits in an AD CS enrollment fallback known as a chase. When a certification authority (CA) cannot obtain an end entity&#8217;s information, the <a href=\"https:\/\/learn.microsoft.com\/en-us\/openspecs\/windows_protocols\/ms-wcce\/f4eb50d5-62f6-470b-8846-9489af9dea62\" target=\"_blank\">Windows enrollment protocol<\/a> lets a request provide <code>cdc<\/code>, the Active Directory server to contact, and <code>rmd<\/code>, the machine object to resolve.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The researchers <a href=\"https:\/\/gist.github.com\/H0j3n\/a5ef2609b5f2944ac2390a191a534c26\" target=\"_blank\">found<\/a> that the CA followed the requester-supplied <code>cdc<\/code> host over Server Message Block (SMB) and Lightweight Directory Access Protocol (LDAP) without first proving it was a real Domain Controller.<\/p>\n<p>An attacker could run rogue Local Security Authority (LSA) and LDAP services, relay the CA&#8217;s authentication challenge to the real Domain Controller over <code>Netlogon<\/code>, and return the target Domain Controller&#8217;s <code>objectSid<\/code> and <code>dNSHostName<\/code>. A controlled machine account supplied the valid domain identity needed for the CA to continue. The CA authenticated that account, then signed the target Domain Controller&#8217;s identity into the certificate.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgz6_WZR93lKBOoxTZvtu7b3fWT03SfhNZtwdqqWDAiolu_H_0WvZAPzpxFYGw_1dgmwDv8ox1oHDC0hiS3H0Wl_ggXkE96K-HbqD7Y39OGnkGnfWqs2GIEmMSlqRiNcZAiHfcri-WCM1PEjeTxY3_XkzgPSiG0FHQ3mac92JE0KgE1n140OwAFb_r93E0\/s1700-e365\/flow.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgz6_WZR93lKBOoxTZvtu7b3fWT03SfhNZtwdqqWDAiolu_H_0WvZAPzpxFYGw_1dgmwDv8ox1oHDC0hiS3H0Wl_ggXkE96K-HbqD7Y39OGnkGnfWqs2GIEmMSlqRiNcZAiHfcri-WCM1PEjeTxY3_XkzgPSiG0FHQ3mac92JE0KgE1n140OwAFb_r93E0\/s1700-e365\/flow.png\" alt=\"\" border=\"0\" data-original-height=\"819\" data-original-width=\"1029\"\/><\/a><\/div>\n<p>The <a href=\"https:\/\/github.com\/aniqfakhrul\/CVE-2026-54121\" target=\"_blank\">public exploit<\/a> automates the chain. It creates a computer account or reuses one specified with <code>--computer-name<\/code>. The tool starts listeners on ports <code>445<\/code> and <code>389<\/code> and relays the CA&#8217;s challenge to the real Domain Controller over <code>Netlogon<\/code>. It then submits the <code>cdc<\/code> and <code>rmd<\/code> attributes and writes a <code>PFX<\/code> file and Kerberos credential cache.<\/p>\n<p>The exploit uses Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) to authenticate as the target Domain Controller. The resulting credential can request account secrets through <code>DCSync<\/code>, including <code>krbtgt<\/code>.<\/p>\n<p>The researchers&#8217; binary analysis found that Microsoft&#8217;s <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-54121\" target=\"_blank\">July update<\/a> adds <code>CRequestInstance::_ValidateChaseTargetIsDC<\/code> to <code>certpdef.dll<\/code> before the CA follows a chase. The validation rejects IP literals, overlong names, and LDAP metacharacters. It also requires exactly one matching Active Directory computer object whose DNS name matches the target and whose <code>userAccountControl<\/code> includes <code>SERVER_TRUST_ACCOUNT<\/code> (<code>8192<\/code>). A later <code>SID<\/code> comparison blocks object substitution.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thn.news\/sygnia-webinar\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhleDdO_4O9-8Pkmidym8Pi9yV4V4jI_M5U0iNRDuoW5Jz3pq7DskZI9OqIChqmY1soaW1ppsC8VLeO55vxSh1m5Q8MJ9ZHuEOSNO5q7K-LwrF6IxrRfCIJOFyoBGaLXGZpkSo8tDirSz-9LmmoOs31tQTlvJWBMLiWJKqMFFaiMmNLV3l-p8zXaFm1VmGG\/s728-e100\/sygnia-d-2.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The public exploit was tested in a Windows Server 2016-or-later forest with an Enterprise CA, the default Machine certificate template, and the default machine-account quota. The <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-54121\" target=\"_blank\">NVD record<\/a> separately lists Windows Server 2012 through Windows Server 2025, including listed Server Core editions, as affected. It also lists Windows 10 versions 1607 and 1809. The flaw was absent from <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">CISA&#8217;s Known Exploited Vulnerabilities catalog<\/a> on July 24.<\/p>\n<p>The researchers reported the flaw to Microsoft on May 14. Microsoft confirmed it on May 22 and patched it on July 14. The researchers publicly disclosed it on July 24. Administrators who cannot patch immediately can clear the chase flag and restart Certificate Services:<\/p>\n<p><code>certutil -setreg policy\\EditFlags -EDITF_ENABLECHASECLIENTDC<\/code><\/p>\n<p><code>Restart-Service CertSvc -Force<\/code><\/p>\n<p>The researchers tested that mitigation only in a controlled lab. They recommend staging it first and treating the July update as the permanent fix.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Jul 24, 2026Vulnerability \/ Enterprise Security Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1999,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[64,2709,1679,1814,83,120,2711,332,2710,826],"class_list":["post-1998","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-active","tag-certighost","tag-controller","tag-directory","tag-domain","tag-exploit","tag-impersonate","tag-lets","tag-lowprivileged","tag-users"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1998","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1998"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1998\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1999"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1998"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1998"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1998"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}