Certighost Exploit Lets Low-Privileged AD Users Impersonate a Domain Controller
Researchers H0j3n and Aniq Fakhrul published a working exploit for Cve 2026 54121 Certighost Adcs (dubbed Certighost, CVSS 8.8) allowing low-privileged Active Directory users to impersonate a Domain Controller and perform DCSync attacks.
Timeline
| Date | Event |
|---|---|
| ~Mid July 2026 | Microsoft patches the AD CS vulnerability in Patch Tuesday |
| 2026-07-24 | Researchers publish working exploit and analysis |
Technical Summary
The exploit targets Microsoft's Active Directory Certificate Services (AD CS). A low-privileged user can: 1. Obtain a certificate for a Domain Controller machine account 2. Authenticate as that Domain Controller 3. Perform a DCSync attack to retrieve the krbtgt secret 4. Achieve full domain compromise
Impact
This is a critical privilege escalation chain for any organisation using AD CS. The exploit turns any authenticated domain user into a potential domain administrator, bypassing traditional security controls.
Australian Significance
AD CS is widely deployed across Australian government and enterprise environments. Organisations should prioritise verifying the July 2026 patches and auditing certificate templates.
Related Pages
- Cve 2026 54121 Certighost Adcs โ The CVE page with full vulnerability details