CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 552

As cited

Copy frozen at (site build).

vulnerabilities

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Mandiant researchers identified a configuration drift vulnerability in Microsoft ADFS environments where manually rotated certificates leave active signing keys exposed in Machine DPAPI, separate from the database records. When AutoCertificateRollover is disabled and administrators perform manual certificate rotation without updating the WID configuration database, attackers can extract the active signing key and forge valid SAML tokens for any user. This technique bypasses traditional detection methods because it avoids interaction with monitored components like LSASS and the live ADFS service process.

Why it matters: Enterprises with manually rotated ADFS certificates and disabled AutoCertificateRollover are at immediate risk of forged SAML token attacks that bypass MFA and conditional access controls, allowing attackers to impersonate any user in Microsoft 365 and Entra ID environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Mandiant researchers discovered that manually rotating ADFS certificates without enabling AutoCertificateRollover can leave active signing keys exposed in Machine DPAPI, creating a configuration drift condition. Attackers exploiting this flaw can extract the private key and forge SAML tokens for any user, bypassing multifactor authentication and conditional access controls. This technique avoids direct interaction with monitored components like LSASS, potentially reducing detection visibility in enterprise environments.

Why it matters: Organizations running ADFS with disabled AutoCertificateRollover and manual certificate rotation are at risk of unauthorized access to SAML-federated applications including Microsoft 365 if attackers obtain the Machine DPAPI-protected signing key; practitioners should verify certificate rotation procedures and enable automatic rollover to prevent configuration drift.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Mandiant researchers discovered that manually rotating ADFS certificates without enabling AutoCertificateRollover can leave active signing keys exposed in Machine DPAPI, creating a configuration drift condition. Attackers exploiting this flaw can extract the private key and forge SAML tokens for any user, bypassing multifactor authentication and conditional access controls. This technique avoids direct interaction with monitored components like LSASS, potentially reducing detection visibility in enterprise environments.

Why it matters: Organizations running ADFS with disabled AutoCertificateRollover and manual certificate rotation are at risk of unauthorized access to SAML-federated applications including Microsoft 365 if attackers obtain the Machine DPAPI-protected signing key; practitioners should verify certificate rotation procedures and enable automatic rollover to prevent configuration drift.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary