<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Adcs on CuraSec</title><link>https://curasec.metacog.co.kr/tags/adcs/</link><description>Recent content in Adcs on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 25 Jul 2026 12:08:50 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/adcs/index.xml" rel="self" type="application/rss+xml"/><item><title>Certighost: Low-Privilege AD User Can Impersonate Domain Controller via ADCS</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-certighost-exploit-lets-low-privileged-active-directory-user/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-certighost-exploit-lets-low-privileged-active-directory-user/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public working exploit now lets any domain user abuse ADCS to obtain a DC certificate and DCSync the krbtgt hash — full domain compromise from low privilege. Immediately audit certificate templates in ADCS for enrollment rights that allow non-admin principals, and restrict or disable any template that can issue DC computer certificates to ordinary users.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Working exploit means this attack path is now within reach of any authenticated user; hunt for ADCS certificate requests from non-computer, non-privileged accounts targeting DC-class templates, and sweep SIEM/EDR for DCSync (DS-Replication-Get-Changes-All) events originating from unexpected principals since July 24.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> No confirmed in-the-wild exploitation yet, but a public PoC dropping a full domain-compromise chain from a low-privilege user is a credible near-term crisis. Ensure your AD/identity team has a remediation task in flight this week, and prepare a brief in case this escalates to customer or board questions the way ADCS misconfigurations have in the past.&lt;/li>
&lt;/ul></description></item></channel></rss>