When Vendor Documentation Creates Critical Attack Paths
ID: 10c2a886-5a11-5160-9950-c6028b1a62eb
STIX ID: report--10c2a886-5a11-5160-9950-c6028b1a62eb
Feed Name: SpecterOps Blog
This research identifies that numerous major vendors' documentation guides administrators to create insecure AD CS certificate templates (ESC1/ESC3/ESC4), enabling low-privileged or authenticated domain principals to obtain certificates that can be abused to impersonate principals, request TGTs, and compromise domains; the report catalogs affected products and vendors, demonstrates abuse with Certify.exe, presents responsible-disclosure timelines, and provides remediation recommendations for vendors and affected organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
