Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
ID: 144a3227-10f2-5612-a353-e9a3f92f9599
STIX ID: report--144a3227-10f2-5612-a353-e9a3f92f9599
Feed Name: The Hacker News
Threat Score
Researchers disclosed 'Certighost' (CVE-2026-54121), an AD CS enrollment fallback (chase) authorization flaw that allows a low-privileged domain user to obtain a Domain Controller certificate and authenticate as that DC via PKINIT — enabling DCSync and theft of the krbtgt secret; Microsoft patched AD CS on July 14 and a public proof-of-concept was released on July 24, with mitigation guidance provided (apply updates or disable chase as a temporary measure).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
