[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcwa-52vzWjyvPxQzya1bzFB_Hvvnn99uOMnvkFtCZvU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"882165ba-7fb0-470a-b04e-205dfe741722","critical-ad-cs-flaw-enables-unauthenticated-privilege-escalation-to-domain-compromise","32cf89cf-0cc9-4756-8d01-c3c70ae981c8","Critical AD CS Flaw Enables Unauthenticated Privilege Escalation to Domain Compromise","The 'Certighost' vulnerability (CVE-2024-26248) in Microsoft Active Directory Certificate Services exposed organizations to unauthenticated privilege escalation, meaning an attacker with no credentials could potentially seize full control of an Active Directory domain. AD CS is a foundational identity and authentication service, making it a high-value target whose compromise undermines the security of every system relying on it. The fact that no authentication was required dramatically lowers the bar for attackers, increasing the urgency of rapid patching. This case underscores how misconfigurations or unpatched flaws in certificate infrastructure can silently erode an organization's entire trust model. Delaying patch application in such critical systems creates a wide window of exposure for ransomware operators and nation-state actors alike.","**Immediate actions:**\n- Apply Microsoft's March 2024 security updates immediately, prioritizing all systems running Active Directory Certificate Services.\n- Audit AD CS configurations to identify and remove unnecessary certificate templates or over-permissive enrollment rights.\n- Restrict network access to AD CS endpoints to only authorized hosts and administrators.\n\n**Long-term improvements:**\n- Establish a formal patch management policy with SLA timelines for critical vulnerabilities (e.g., patch within 24–72 hours for CVSS 9+).\n- Implement the principle of least privilege across all AD CS roles, templates, and enrollment permissions.\n- Conduct regular AD CS security reviews using tools such as Certify or PSPKIAudit to detect misconfigurations proactively.\n\n**Detection measures:**\n- Enable and centralize logging of all AD CS certificate issuance events and forward them to your SIEM for anomaly detection.\n- Configure alerts for unusual certificate requests, especially those involving high-privilege templates or machine accounts.\n- Deploy a vulnerability scanner capable of identifying unpatched AD CS instances across the enterprise on a scheduled basis.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 7: Continuous Vulnerability Management","CIS Control 5: Account Management (Least Privilege)","CIS Control 8: Audit Log Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 AU-12: Audit Record Generation","NIST SP 800-53 IA-5: Authenticator Management","NIST CSF ID.RA-1: Asset Vulnerabilities Identified","NIST CSF PR.AC-4: Access Permissions Managed","MITRE ATT&CK T1649: Steal or Forge Authentication Certificates","ITIL 4: Change Enablement (Emergency Change Procedures)","MS-ISAC Critical Security Control: Patch and Vulnerability Management","published","2026-07-28T18:20:59.554639+00:00","2026-07-28T18:20:59.448+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.darkreading.com\u002Fvulnerabilities-threats\u002Fcertighost-flaw-microsoft-active-directory-certificates","certighost-flaw-haunts-microsoft-active-directory-certificates-af56a0","'Certighost' Flaw Haunts Microsoft Active Directory Certificates",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":45,"name":46,"slug":47,"description":48,"color":49},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]