New Certighost PoC exploit lets attackers hijack Windows domains

New Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit for Certighost, tracked as CVE-2026-54121, shows how an authenticated attacker could abuse Active Directory Certificate Services to impersonate a domain controller and potentially compromise a Windows domain. Microsoft fixed the flaw in the July 2026 Patch Tuesday updates, while researchers H0j3n and Aniq Fakhrul released technical details and an exploit demonstrating domain-level compromise. #Certighost #CVE-2026-54121 #H0j3n #AniqFakhrul #ActiveDirectoryCertificateServices

Keypoints

  • Certighost is an AD CS vulnerability that can let an authenticated attacker impersonate a machine account or domain controller.
  • The flaw was tracked as CVE-2026-54121 and patched by Microsoft in July 2026.
  • The attack abuses the AD CS chase mechanism using the cdc and rmd certificate request values.
  • A rogue attacker-controlled endpoint can trick the CA into issuing a certificate for a targeted domain controller account.
  • The proof-of-concept automates PKINIT authentication and can lead to DCSync and krbtgt credential theft.

Read More: https://www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains/