Certighost: How a low-privileged AD user can impersonate a Domain Controller

Colleagues, I’d like to flag a notable cybersecurity development.
Researchers have demonstrated a working AD CS exploit, Certighost.
It enables an ordinary Active Directory user, through a chain of flaws, to obtain a Domain Controller certificate and authenticate as a machine.
From there, DCSync becomes possible, allowing secrets to be extracted, including krbtgt.
Microsoft released a patch on 14 July for CVE-2026-54121.
If immediate remediation is not possible, researchers recommend temporarily disabling chase fallback and testing the change in a lab.
Why this matters: the issue undermines trust in the domain infrastructure and can lead to full AD compromise.
Have you already reviewed AD CS in your environment?
#cybersecurity #ADCS #ActiveDirectory #Microsoft


Latest comments
No comments yet.