logo

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

ID: 144a3227-10f2-5612-a353-e9a3f92f9599

STIX ID: report--144a3227-10f2-5612-a353-e9a3f92f9599

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed 'Certighost' (CVE-2026-54121), an AD CS enrollment fallback (chase) authorization flaw that allows a low-privileged domain user to obtain a Domain Controller certificate and authenticate as that DC via PKINIT — enabling DCSync and theft of the krbtgt secret; Microsoft patched AD CS on July 14 and a public proof-of-concept was released on July 24, with mitigation guidance provided (apply updates or disable chase as a temporary measure).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.