VulnerabilitiesJul 28, 2026
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
Microsoft patched a high-severity flaw in Active Directory certificate services.
Summary
Microsoft has addressed a critical vulnerability, tracked as CVE-2024-26248, affecting its Active Directory Certificate Services (AD CS). This flaw allows an unauthenticated attacker to escalate privileges within an Active Directory environment, potentially leading to a full domain compromise. The vulnerability was patched in Microsoft's March 2024 security updates.
Indicators of Compromise
- cve — CVE-2024-26248
Entities
Active Directory Certificate Services (product)Microsoft (vendor)Active Directory (technology)