VMTech
Discuss a project

Certighost: How a low-privileged AD user can impersonate a Domain Controller

Certighost: How a low-privileged AD user can impersonate a Domain Controller

Colleagues, I’d like to flag a notable cybersecurity development.

Researchers have demonstrated a working AD CS exploit, Certighost.

It enables an ordinary Active Directory user, through a chain of flaws, to obtain a Domain Controller certificate and authenticate as a machine.

From there, DCSync becomes possible, allowing secrets to be extracted, including krbtgt.

Microsoft released a patch on 14 July for CVE-2026-54121.

If immediate remediation is not possible, researchers recommend temporarily disabling chase fallback and testing the change in a lab.

Why this matters: the issue undermines trust in the domain infrastructure and can lead to full AD compromise.

Have you already reviewed AD CS in your environment?
#cybersecurity #ADCS #ActiveDirectory #Microsoft

Certighost in AD CS: what defenders should review next

The key issue is not simply access by a low-privileged user. Certighost demonstrates how an AD CS exploit chain can cross a trust boundary, obtain a Domain Controller certificate and enable authentication as a machine.

How the Certighost attack path develops

The reported chain connects certificate issuance, machine authentication and domain replication privileges. This makes the AD CS configuration and remediation status central to the review.

  • The attack begins with an ordinary Active Directory user.
  • The exploit chain can obtain a Domain Controller certificate.
  • That certificate can enable authentication as a machine.
  • DCSync can then expose secrets, including krbtgt.

A practical review sequence

Treat the response as a controlled infrastructure change. Establish whether AD CS is present, confirm the remediation status for CVE-2026-54121 and document any temporary measure before changing production systems.

  • Identify where AD CS is deployed in the environment.
  • Confirm whether the Microsoft patch released on 14 July has been applied.
  • If patching is delayed, assess the recommended chase fallback change.
  • Test any temporary configuration change in a lab first.
  • Record the remediation decision and validation result.

Why this matters for domain trust

A Domain Controller certificate represents a highly trusted identity. If a low-privileged account can reach that identity through the Certighost AD CS chain, the result can extend beyond the original user and affect the wider domain infrastructure.

  • The initial account privilege does not reflect the final impact.
  • Certificate trust is a central part of the demonstrated chain.
  • Exposure of krbtgt can indicate full domain compromise.

Frequently asked questions

What is Certighost?

Certighost is a demonstrated AD CS exploit chain in which a low-privileged Active Directory user can obtain a Domain Controller certificate and authenticate as a machine.

Why is Certighost serious for Active Directory?

The reported chain can make DCSync possible and expose domain secrets, including krbtgt. This undermines trust in the domain infrastructure and can lead to full AD compromise.

Which vulnerability is associated with this issue?

The page identifies CVE-2026-54121 and notes that Microsoft released a patch on 14 July.

What can teams do if immediate remediation is not possible?

Researchers recommend temporarily disabling chase fallback. The change should be tested in a lab before it is considered for a production environment.

Does having a low-privileged AD user automatically mean the domain is compromised?

No. The report describes an exploit chain, not automatic compromise from account access alone. Teams should review their AD CS environment and confirm the applicable remediation status.

Open analytics
On the site 15 views
min read 1 24.07.2026
On Instagram 2 views
On Instagram 1 reach
Instagram

Certighost: How a low-privileged AD user can impersonate a Domain Controller

Open the post on Instagram ↗