CuraSec

Act archived

Certighost: Low-Privilege AD User Can Impersonate Domain Controller via ADCS

2026-07-25 12:08 UTC · The Hacker News · read the source ↗ #active-directory#adcs#privilege-escalation
  • Engineer — Act: A public working exploit now lets any domain user abuse ADCS to obtain a DC certificate and DCSync the krbtgt hash — full domain compromise from low privilege. Immediately audit certificate templates in ADCS for enrollment rights that allow non-admin principals, and restrict or disable any template that can issue DC computer certificates to ordinary users.
  • SOC/IR — Act: Working exploit means this attack path is now within reach of any authenticated user; hunt for ADCS certificate requests from non-computer, non-privileged accounts targeting DC-class templates, and sweep SIEM/EDR for DCSync (DS-Replication-Get-Changes-All) events originating from unexpected principals since July 24.
  • Leader — Plan: No confirmed in-the-wild exploitation yet, but a public PoC dropping a full domain-compromise chain from a low-privilege user is a credible near-term crisis. Ensure your AD/identity team has a remediation task in flight this week, and prepare a brief in case this escalates to customer or board questions the way ADCS misconfigurations have in the past.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.