VMTech
+381 11 4183 54024/7 Discuss a project
← All Instagram insights VMTECH · INSTAGRAM

Certighost: How a low-privileged AD user can impersonate a Domain Controller

Certighost: How a low-privileged AD user can impersonate a Domain Controller

Colleagues, I’d like to flag a notable cybersecurity development.

Researchers have demonstrated a working AD CS exploit, Certighost.

It enables an ordinary Active Directory user, through a chain of flaws, to obtain a Domain Controller certificate and authenticate as a machine.

From there, DCSync becomes possible, allowing secrets to be extracted, including krbtgt.

Microsoft released a patch on 14 July for CVE-2026-54121.

If immediate remediation is not possible, researchers recommend temporarily disabling chase fallback and testing the change in a lab.

Why this matters: the issue undermines trust in the domain infrastructure and can lead to full AD compromise.

Have you already reviewed AD CS in your environment?
#cybersecurity #ADCS #ActiveDirectory #Microsoft

Current metrics
0Views
0Reach
0Likes
0Comments
0Saved
0Shares

Latest comments

No comments yet.

Instagram

Certighost: How a low-privileged AD user can impersonate a Domain Controller

Open the post on Instagram ↗