Certighost AD CS Vulnerability Exposes Active Directory

Certighost AD CS vulnerability exploit diagram showing Active Directory domain takeover

A certificate issued to the wrong machine can transform a standard account into a domain takeover weapon. Recently, security researchers H0j3n and Aniq Fakhrul demonstrated this alarming scenario through the Certighost vulnerability. Consequently, an unprivileged user can request a domain controller certificate and authenticate seamlessly as the server itself.

Understanding CVE-2026-54121 and AD CS Risks

Designated as CVE-2026-54121, this critical vulnerability afflicts Active Directory Certificate Services (AD CS). Microsoft classified the flaw as an access control bypass, assigning it a CVSS severity score of 8.8. Furthermore, Microsoft released an official patch on July 14, followed by a public proof-of-concept demonstration on July 24.

Crucially, the attack requires no administrative privileges. An attacker merely needs network access and a standard Domain Users account. In lab testing, researchers utilized a standard account to register a new computer object via ms-DS-MachineAccountQuota. Alternatively, an attacker can leverage an existing compromised machine account.

Mechanics of the Certighost Exploit Chain

The exploit targets the “chase” mechanism within AD CS certificate issuance workflows. When a certificate authority cannot locate target object details, Windows protocols allow the request to specify an Active Directory server. Consequently, researchers discovered that AD CS contacts the specified server via SMB and LDAP without verifying if it represents a genuine domain controller.

According to a proof-of-concept exploit published by H0j3n, an attacker can run spoofed LSA and LDAP services. Subsequently, the attacker relays the certificate authority’s authentication request to the legitimate domain controller via Netlogon. Therefore, the certificate authority signs a valid domain controller certificate for the attacker.

Domain Takeover via DCSync and Mitigation

Armed with this forged certificate, the attacker authenticates via Kerberos PKINIT as the domain controller. Consequently, the adversary extracts domain secrets via DCSync, compromising the vital krbtgt account key. The automated tool orchestrates this entire attack chain across Windows Server 2016 and newer forests.

To neutralize this threat, administrators should apply Microsoft’s July security updates immediately. Additionally, organizations can temporarily disable the referral chase mechanism during testing if patching requires delay. Ultimately, applying Microsoft’s official update remains the only permanent resolution.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply