INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Certighost Exploit Lets Low-Privileged Users Impersonate Domain Controllers

| 2026-07-28 16:38 HIGH HIGH
Executive Summary AI-generated
The newly discovered "Certighost" flaw in Microsoft's Active Directory Certificate Services (AD CS) has the potential to compromise enterprise environments by allowing low-privileged domain users to impersonate domain controllers and access sensitive information. This vulnerability stems from a broken trust boundary within the AD CS certificate enrollment process, which researchers Aniq Fakhrul and Muhammad Ali exploited in their proof-of-concept attack. The flaw affects Microsoft's Active Directory Certificate Services, making it possible for attackers to manipulate client DC requests and query an attacker-controlled host for domain controller identity information. This could lead to unauthorized access to sensitive data and potentially disrupt AD operations.
Technical Mitigations AI-generated
* Implement Certificate Revocation Lists (CRLs) and Online Public Key Infrastructure (OPPI): Microsoft recommends implementing CRLs and OPPI to ensure that certificates are revoked promptly when they expire or are compromised. This can help prevent certificate-based attacks like Certighost. * Use Strong Password Policies: Enforcing strong password policies, such as requiring complex passwords and multi-factor authentication, can reduce the risk of a low-privileged domain user impersonating a Domain Controller using Certighost. * Regularly Update and Patch Operating Systems and Software: Keeping operating systems and software up to date with the latest security patches can help prevent exploitation of vulnerabilities like Certighost that Microsoft patched in its July 2026 Patch Tuesday updates. * Implement Network Segmentation and Isolation: Segmenting networks and isolating sensitive areas, such as Domain Controllers, can reduce the risk of a compromised certificate being used to impersonate a Domain Controller using Certighost.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-54121CVE-2026-54121
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎May 14
Microsoft fixed the Certighost flaw allowing domain controller impersonation on May 14.
organisation the Microsoft Security Response Center
‎May 22
Microsoft confirmed the vulnerability on May 22 and patched it on July 14.
organisation the Microsoft Security Response Center
‎May 2026
Researchers H0j3n and Aniq Fakhrul reported the issue to Microsoft in May 2026, and the company released a fix on July 14, 2026.
organisation Aniq Fakhrul
‎July 14
Microsoft patched a vulnerability in its Certighost software allowing domain controller impersonation on July 14.
‎July 14, 2026
Microsoft released a fix for the Certighost flaw allowing domain controller impersonation on July 14, 2026.
organisation Aniq Fakhrul
‎Jul 24, 2026
Microsoft released a security patch to fix the Certighost flaw, allowing threat actors to impersonate domain controllers.
‎July 24
Researchers H0j3n and Aniq Fakhrul published a working exploit that allowed low-privileged Active Directory users to obtain certificates for Domain Controllers and authenticate as those machines.
organisation Aniq Fakhrul
organisation Active Directory
organisation Vulnerability / Enterprise Security
general_metric 24  Khandelwal  Jul
organisation The Hacker News
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎2026/07/28
Threat actors exploited a vulnerability in Microsoft's Certighost software to gain unauthorized access to domain controllers.
‎2026/07/28
Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation.
organisation PoC
organisation Microsoft
organisation Active Directory Certificate Services
organisation Active Directory Certificate Services
organisation the Active Directory Certificate Services
infrastructure Windows
organisation the Active Directory
infrastructure 2016 Server
organisation NVD
organisation Certificate Authority Trusted
organisation cdc
organisation Lightweight Directory Access Protocol
organisation Domain Controller
organisation Aniq Fakhrul
organisation Certighost
organisation CVSS
organisation Certighost'
organisation Microsoft Active Directory Certificates
organisation Microsoft AD Services
organisation CA
organisation DNS
organisation SID
organisation LSA
organisation Local Security Authority
organisation Netlogon
organisation Fakhrul
organisation Certificate Authority
organisation Certighost Abuses a Trust Boundary
organisation OAuth
organisation PKI
organisation Active Directory
organisation HTTPS
organisation the Key Distribution Center
organisation KDC
organisation pyasn1
organisation Microsoft Fixes Certighost
organisation a Certification Authority
organisation Domain Controllers
organisation Machine
organisation Chase
organisation SMB
organisation PFX
organisation IP
organisation Certificate Services
organisation Restart-Service
‎July 2026
Microsoft fixes a critical vulnerability in Certighost, allowing threat actors to impersonate domain controllers.
‎2051/07/22
Threat actors exploited a previously unknown vulnerability in Microsoft's Certighost software to gain unauthorized access and impersonate domain controllers.
target_region United States
general_metric 25 Years
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
2,016
Server