Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers H0j3n and Aniq Fakhrul disclosed Certighost, a flaw in Active Directory Certificate Services that can let a low-privileged user obtain a Domain Controller certificate and escalate to DCSync. Microsoft patched the issue as CVE-2026-54121 in its July 14 update, and the researchers also published a proof-of-concept exploit that automates the attack chain. #Certighost #CVE-2026-54121 #ActiveDirectoryCertificateServices #DomainController #DCSync

Keypoints

  • Certighost lets a low-privileged Active Directory user obtain a certificate for a Domain Controller.
  • The resulting Kerberos credential can be used to perform DCSync and retrieve krbtgt.
  • The flaw affected AD CS chase fallback behavior and was patched as CVE-2026-54121.
  • Exploitation required network access, a domain account, and an Enterprise CA with the vulnerable enrollment path.
  • The public exploit used rogue SMB and LDAP listeners to relay authentication and issue a PFX file and Kerberos cache.

Read More: https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html