As cited
Copy frozen at (site build).
vulnerabilities
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
Mandiant researchers identified a configuration drift vulnerability in Microsoft ADFS environments where manually rotated certificates leave active signing keys exposed in Machine DPAPI, separate from the database records. When AutoCertificateRollover is disabled and administrators perform manual certificate rotation without updating the WID configuration database, attackers can extract the active signing key and forge valid SAML tokens for any user. This technique bypasses traditional detection methods because it avoids interaction with monitored components like LSASS and the live ADFS service process.
Why it matters: Enterprises with manually rotated ADFS certificates and disabled AutoCertificateRollover are at immediate risk of forged SAML token attacks that bypass MFA and conditional access controls, allowing attackers to impersonate any user in Microsoft 365 and Entra ID environments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
Mandiant researchers discovered that manually rotating ADFS certificates without enabling AutoCertificateRollover can leave active signing keys exposed in Machine DPAPI, creating a configuration drift condition. Attackers exploiting this flaw can extract the private key and forge SAML tokens for any user, bypassing multifactor authentication and conditional access controls. This technique avoids direct interaction with monitored components like LSASS, potentially reducing detection visibility in enterprise environments.
Why it matters: Organizations running ADFS with disabled AutoCertificateRollover and manual certificate rotation are at risk of unauthorized access to SAML-federated applications including Microsoft 365 if attackers obtain the Machine DPAPI-protected signing key; practitioners should verify certificate rotation procedures and enable automatic rollover to prevent configuration drift.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
Mandiant researchers discovered that manually rotating ADFS certificates without enabling AutoCertificateRollover can leave active signing keys exposed in Machine DPAPI, creating a configuration drift condition. Attackers exploiting this flaw can extract the private key and forge SAML tokens for any user, bypassing multifactor authentication and conditional access controls. This technique avoids direct interaction with monitored components like LSASS, potentially reducing detection visibility in enterprise environments.
Why it matters: Organizations running ADFS with disabled AutoCertificateRollover and manual certificate rotation are at risk of unauthorized access to SAML-federated applications including Microsoft 365 if attackers obtain the Machine DPAPI-protected signing key; practitioners should verify certificate rotation procedures and enable automatic rollover to prevent configuration drift.
- Source published
- First seen by Cybersecurity Tracker