Researchers H0j3n and Aniq Fakhrul disclosed Certighost, a flaw in Active Directory Certificate Services that can let a low-privileged user obtain a Domain Controller certificate and escalate to DCSync. Microsoft patched the issue as CVE-2026-54121 in its July 14 update, and the researchers also published a proof-of-concept exploit that automates the attack chain. #Certighost #CVE-2026-54121 #ActiveDirectoryCertificateServices #DomainController #DCSync
Keypoints
- Certighost lets a low-privileged Active Directory user obtain a certificate for a Domain Controller.
- The resulting Kerberos credential can be used to perform DCSync and retrieve krbtgt.
- The flaw affected AD CS chase fallback behavior and was patched as CVE-2026-54121.
- Exploitation required network access, a domain account, and an Enterprise CA with the vulnerable enrollment path.
- The public exploit used rogue SMB and LDAP listeners to relay authentication and issue a PFX file and Kerberos cache.
Read More: https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html