Certighost CVE-2026-54121 Lets Low-Privilege Users Hijack Windows Domains via AD CS
A publicly available proof-of-concept exploit for CVE-2026-54121, dubbed Certighost, allows a low-privilege domain user to fully compromise a Windows domain through Active Directory Certificate Services. The attacker creates a machine account, runs fake LDAP and LSA services, and tricks the Enterprise CA into issuing a certificate containing a real Domain Controller's SID and DNS name. Using that certificate, the attacker authenticates via PKINIT to obtain a Kerberos TGT as the DC, then performs a DCSync attack to steal domain secrets including the krbtgt hash. Microsoft's July 2026 security update addresses the flaw by requiring the CA to verify the target DC identity and enforce SID matching during certificate issuance. Organizations are advised to apply the patch promptly, restrict machine account creation, and limit CA egress traffic, as successful exploitation should be treated as a total domain compromise.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in