Certighost Exploit Can Compromise Windows Domains
The Certighost vulnerability could allow a low-privileged Windows domain user to impersonate a domain controller and compromise an entire Active Directory environment.
Researchers have released a proof-of-concept exploit for the Windows Active Directory Certificate Services flaw, tracked as CVE-2026-54121. Microsoft fixed the vulnerability in its July 2026 Patch Tuesday security updates.
Certighost could expose critical domain credentials
Certighost affected Active Directory Certificate Services, which issues certificates for authentication and secure communications across Windows domains.
An authenticated attacker could manipulate machine-account attributes and request a certificate representing another computer. The attacker could then use that certificate for authentication through PKINIT.
Targeting a domain controller account could let the attacker authenticate as the domain controller and perform highly privileged Active Directory operations.
Researchers demonstrated that the compromised identity could support requests for replicated directory secrets. This could expose sensitive credentials, including those connected to the krbtgt account.
How the Certighost vulnerability worked
The vulnerability affected an optional certificate-enrollment fallback process that researchers called the chase mechanism.
During this process, the Certification Authority used supplied values to determine which server it should contact and which account it should locate. However, it did not adequately confirm that the server represented a legitimate domain controller.
An attacker-controlled system could therefore return false identity information for a targeted machine account.
The attacker still needed valid domain authentication. A low-privileged user could create a machine account when administrators retained the default ms-DS-MachineAccountQuota setting.
That machine account could satisfy authentication requirements during the certificate request while the attacker targeted a more privileged computer account.
Proof-of-concept exploit released
Researchers reported Certighost to Microsoft on May 14, 2026. Microsoft addressed the issue in the July security updates before the researchers published technical details and proof-of-concept code.
The exploit automates the certificate-request and authentication stages. Testing showed that a low-privileged domain user could impersonate a domain controller under certain AD CS configurations and gain domain-level administrative capabilities.
Microsoft adds stricter AD CS validation
Microsoft updated the chase process so Certification Authorities confirm that the supplied server maps to a legitimate domain controller in Active Directory.
The identity returned by the server must also match the account expected by the certificate request.
Administrators should install the July 2026 security updates as soon as possible. Organizations that cannot update immediately can disable the optional chase fallback mechanism, although researchers warned that this workaround has not received full production testing.
The workaround should only serve as temporary protection until administrators can apply Microsoft’s security updates.
In other security news, fake Windows app websites are targeting users searching for PowerToys, Wintoys, and similar tools. Hackers have also used Steam forums to distribute the XMRig cryptocurrency miner.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages