A proof-of-concept exploit for Certighost, tracked as CVE-2026-54121, shows how an authenticated attacker could abuse Active Directory Certificate Services to impersonate a domain controller and potentially compromise a Windows domain. Microsoft fixed the flaw in the July 2026 Patch Tuesday updates, while researchers H0j3n and Aniq Fakhrul released technical details and an exploit demonstrating domain-level compromise. #Certighost #CVE-2026-54121 #H0j3n #AniqFakhrul #ActiveDirectoryCertificateServices
Keypoints
- Certighost is an AD CS vulnerability that can let an authenticated attacker impersonate a machine account or domain controller.
- The flaw was tracked as CVE-2026-54121 and patched by Microsoft in July 2026.
- The attack abuses the AD CS chase mechanism using the cdc and rmd certificate request values.
- A rogue attacker-controlled endpoint can trick the CA into issuing a certificate for a targeted domain controller account.
- The proof-of-concept automates PKINIT authentication and can lead to DCSync and krbtgt credential theft.