As cited
Copy frozen at (site build).
vulnerabilities
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers published a working exploit on July 24 that enables low-privileged Active Directory users to obtain a Domain Controller certificate and authenticate as that machine, a flaw called Certighost. The resulting Kerberos credential can retrieve the krbtgt secret through DCSync, which Domain Controller accounts possess directory replication rights to access.
Why it matters: Active Directory administrators need to assess whether low-privileged users in their environment can exploit Certighost to escalate to domain controller impersonation and extract the krbtgt secret, which would compromise the entire directory.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers published a working exploit on July 24 that enables low-privileged Active Directory users to obtain a Domain Controller certificate and authenticate as that machine, a flaw called Certighost. The resulting Kerberos credential can retrieve the krbtgt secret through DCSync, which Domain Controller accounts possess directory replication rights to access.
Why it matters: Active Directory administrators need to assess whether low-privileged users in their environment can exploit Certighost to escalate to domain controller impersonation and extract the krbtgt secret, which would compromise the entire directory.
- Source published
- First seen by Cybersecurity Tracker