Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on lemmy.world
microsoft·MicrosoftbyUnLocoPoco

Certighost: A New AD CS Attack That Can Lead to Full Active Directory Compromise

cross-posted from: https://lemmy.world/post/49907053

A newly disclosed vulnerability in Active Directory Certificate Services (AD CS) shows just how dangerous certificate-based authentication can become when trust breaks down. Certighost (CVE-2026-54121) allows a low-privileged domain user, under specific conditions, to obtain a certificate for a Domain Controller, authenticate using PKINIT, and perform DCSync to retrieve the krbtgt secret, potentially leading to complete Active Directory compromise. Microsoft patched the flaw in its July 2026 security updates, but a public proof-of-concept is now available

Certighost: A New AD CS Attack That Can Lead to Full Active Directory Compromisehttps://thecybersecguru.com/news/certighost-cve-2026-54121-ad-cs-domain-controller-impersonation/Open linkView original on lemmy.world
3

No replies yet

No comments on the original post yet.