CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3181

As cited

Copy frozen at (site build).

vulnerabilities

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers published a working exploit on July 24 that enables low-privileged Active Directory users to obtain a Domain Controller certificate and authenticate as that machine, a flaw called Certighost. The resulting Kerberos credential can retrieve the krbtgt secret through DCSync, which Domain Controller accounts possess directory replication rights to access.

Why it matters: Active Directory administrators need to assess whether low-privileged users in their environment can exploit Certighost to escalate to domain controller impersonation and extract the krbtgt secret, which would compromise the entire directory.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers published a working exploit on July 24 that enables low-privileged Active Directory users to obtain a Domain Controller certificate and authenticate as that machine, a flaw called Certighost. The resulting Kerberos credential can retrieve the krbtgt secret through DCSync, which Domain Controller accounts possess directory replication rights to access.

Why it matters: Active Directory administrators need to assess whether low-privileged users in their environment can exploit Certighost to escalate to domain controller impersonation and extract the krbtgt secret, which would compromise the entire directory.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary