thecybersecguru
@thecybersecguru@infosec.exchange
infosec.exchange
🚨 Low-privileged Active Directory user → Full Domain Admin?
A new AD CS vulnerability called Certighost (CVE-2026-54121) makes it possible.
The attack abuses the certificate enrollment "chase" mechanism to obtain a Domain Controller certificate, authenticate via PKINIT, perform DCSync, and ultimately extract the krbtgt secret for complete Active Directory compromise.
✅ No admin privileges required
✅ Public PoC available
✅ Patched by Microsoft, but unpatched Enterprise CAs remain at risk
I break down:
• How the exploit works internally
• Why AD CS trusts the wrong host
• PKINIT → DCSync attack chain
• Microsoft's patch and new validation logic
• Detection and mitigation guidance
🔗 https://thecybersecguru.com/news/certighost-cve-2026-54121-ad-cs-domain-controller-impersonation/
#CyberSecurity #ActiveDirectory #ADCS #WindowsServer #Microsoft #PKINIT #Kerberos #DCSync #CVE202654121 #CVE #BlueTeam #RedTeam #ThreatDetection #InfoSec #SOC #Windows #Pentest #DFIR #CyberDefense
https://sekurak.pl Account by @kkrenski