logo

EKUwu: Not just another AD CS ESC

ID: 0dfabdf4-d6be-561c-bfcd-381a3e63626a

STIX ID: report--0dfabdf4-d6be-561c-bfcd-381a3e63626a

Feed Name: TrustedSec blog

Threat Score
85/100

Date Published: 2025-03-27

Date Updated: 2026-05-01

...
...

This report describes CVE-class AD CS vulnerability (EKUwu / ESC15) in default version 1 certificate templates that allows an attacker with enrollment rights to inject Microsoft Application Policies into issued certificates, overriding EKU restrictions and enabling client authentication, certificate request agent, and code signing certs—facilitating privilege escalation and domain compromise; the issue was reported to MSRC, weaponized in community tools, and has been patched with recommended mitigations such as disabling vulnerable version 1 templates or cloning them to version 2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.