Back to all lessons
Awareness Lessons
3 months ago

Certighost: Critical AD CS Flaw Enables Domain Controller Impersonation

The Certighost vulnerability (CVE-2026-54121) exposes a fundamental weakness in Active Directory Certificate Services, where insufficient validation of identity data allowed a low-privilege user to obtain a certificate impersonating a Domain Controller. This matters because certificate-based trust is foundational to Active Directory security — once an attacker holds a DC certificate, they can execute DCSync attacks to extract credential hashes for every account in the domain, achieving full domain compromise. The root issue lies in the Certification Authority's failure to enforce strict controls over attacker-controllable identity attributes during certificate enrollment. This class of AD CS vulnerability (similar to ESC family attacks) has become a prime target for ransomware operators and nation-state actors due to its high impact and often-overlooked attack surface.

Tactical Insight

Immediate actions

  • Apply Microsoft's patch for CVE-2026-54121 to all Active Directory Certificate Services instances without delay.
  • Audit all currently issued certificates for anomalous Subject Alternative Names (SANs) or UPN values that could indicate prior exploitation.
  • Temporarily restrict certificate enrollment permissions to the minimum necessary roles while patching is validated.

Long-term improvements

  • Harden AD CS by enabling and enforcing Manager Approval for sensitive certificate templates (especially those allowing DC impersonation).
  • Regularly run AD CS-specific auditing tools (e.g., Certify, PKIAudit) to detect misconfigured or abusable certificate templates.
  • Implement least-privilege principles for all certificate enrollment rights, removing low-privilege users from high-risk templates.

Detection measures

  • Enable and monitor Windows Event Logs 4886 (certificate requested) and 4887 (certificate issued) for anomalous enrollment patterns.
  • Alert on DCSync activity (Event ID 4662 with specific replication permissions) as an indicator of post-exploitation.
  • Integrate AD CS telemetry into your SIEM to detect unusual certificate issuance for machine or DC account types.