Back to all lessons
Awareness Lessons
2 months ago

AD Certificate Services Flaw Enables Full Domain Compromise via Privilege Escalation

Certighost (CVE-2026-54121) exploits a critical flaw in Microsoft Active Directory Certificate Services (AD CS), allowing any low-privileged domain user to obtain a certificate that impersonates a Domain Controller. By leveraging the PKINIT authentication protocol, an attacker can then authenticate as the Domain Controller itself, achieving full domain compromise with minimal initial access. This attack highlights the dangerous trust placed in PKI infrastructure — when the certificate authority is misconfigured or unpatched, it becomes the master key to the entire domain. The severity is compounded by how widely AD CS is deployed and how quietly it operates, often without robust monitoring. Microsoft has released a patch, making rapid deployment essential for every affected organization.

Tactical Insight

Immediate actions

  • Apply Microsoft's released patch for CVE-2026-54121 to all systems running Active Directory Certificate Services without delay.
  • Audit all existing certificate templates to identify and revoke any certificates that may have been issued to low-privileged users impersonating Domain Controllers.
  • Run tools such as Certify or PSPKIAudit to enumerate misconfigured or overly permissive certificate templates across your AD CS environment.

Long-term improvements

  • Enforce the principle of least privilege on certificate enrollment permissions so only authorized accounts can request sensitive certificate types.
  • Implement Certificate Authority Web Enrollment restrictions and require manager approval for any certificate template that grants Domain Controller-level authentication.
  • Regularly audit and harden AD CS configurations using Microsoft's recommended baselines and CIS benchmarks for PKI infrastructure.

Detection measures

  • Enable and monitor Windows Event Logs (Event IDs 4886, 4887, 4768) to detect anomalous certificate requests and PKINIT-based Kerberos authentications.
  • Deploy a SIEM alert for any certificate issued to a non-DC account that includes the 'Domain Controller Authentication' or 'Kerberos Authentication' EKU.
  • Integrate AD CS telemetry into your threat detection pipeline to baseline normal certificate issuance behavior and flag deviations.