INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Certighost Exploit Lets Low-Privileged Users Impersonate Domain Controllers
| 2026-07-28 16:38 HIGH HIGHExecutive Summary AI-generated
The newly discovered "Certighost" flaw in Microsoft's Active Directory Certificate Services (AD CS) has the potential to compromise enterprise environments by allowing low-privileged domain users to impersonate domain controllers and access sensitive information. This vulnerability stems from a broken trust boundary within the AD CS certificate enrollment process, which researchers Aniq Fakhrul and Muhammad Ali exploited in their proof-of-concept attack. The flaw affects Microsoft's Active Directory Certificate Services, making it possible for attackers to manipulate client DC requests and query an attacker-controlled host for domain controller identity information. This could lead to unauthorized access to sensitive data and potentially disrupt AD operations.
Technical Mitigations AI-generated
* Implement Certificate Revocation Lists (CRLs) and Online Public Key Infrastructure (OPPI): Microsoft recommends implementing CRLs and OPPI to ensure that certificates are revoked promptly when they expire or are compromised. This can help prevent certificate-based attacks like Certighost.
* Use Strong Password Policies: Enforcing strong password policies, such as requiring complex passwords and multi-factor authentication, can reduce the risk of a low-privileged domain user impersonating a Domain Controller using Certighost.
* Regularly Update and Patch Operating Systems and Software: Keeping operating systems and software up to date with the latest security patches can help prevent exploitation of vulnerabilities like Certighost that Microsoft patched in its July 2026 Patch Tuesday updates.
* Implement Network Segmentation and Isolation: Segmenting networks and isolating sensitive areas, such as Domain Controllers, can reduce the risk of a compromised certificate being used to impersonate a Domain Controller using Certighost.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-54121CVE-2026-54121
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
May 14
Microsoft fixed the Certighost flaw allowing domain controller impersonation on May 14.
Click on any entity below to view its context and source!
organisation
the Microsoft Security Response Center
Patching and Mitigation
The researchers reported the flaw to the Microsoft Security Response Center on May 14, and by May 22 the company had investigated and confirmed the vulnerability.
May 22
Microsoft confirmed the vulnerability on May 22 and patched it on July 14.
Click on any entity below to view its context and source!
organisation
the Microsoft Security Response Center
Patching and Mitigation
The researchers reported the flaw to the Microsoft Security Response Center on May 14, and by May 22 the company had investigated and confirmed the vulnerability.
May 2026
Researchers H0j3n and Aniq Fakhrul reported the issue to Microsoft in May 2026, and the company released a fix on July 14, 2026.
Click on any entity below to view its context and source!
organisation
Aniq Fakhrul
Researchers H0j3n and Aniq Fakhrul reported it to Microsoft in May 2026, and the company
released a fix on July 14, 2026
.
July 14
Microsoft patched a vulnerability in its Certighost software allowing domain controller impersonation on July 14.
July 14, 2026
Microsoft released a fix for the Certighost flaw allowing domain controller impersonation on July 14, 2026.
Click on any entity below to view its context and source!
organisation
Aniq Fakhrul
Researchers H0j3n and Aniq Fakhrul reported it to Microsoft in May 2026, and the company
released a fix on July 14, 2026
.
Jul 24, 2026
Microsoft released a security patch to fix the Certighost flaw, allowing threat actors to impersonate domain controllers.
July 24
Researchers H0j3n and Aniq Fakhrul published a working exploit that allowed low-privileged Active Directory users to obtain certificates for Domain Controllers and authenticate as those machines.
Click on any entity below to view its context and source!
organisation
Aniq Fakhrul
Swati Khandelwal
Jul 24, 2026
Vulnerability / Enterprise Security
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.
organisation
Active Directory
Swati Khandelwal
Jul 24, 2026
Vulnerability / Enterprise Security
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.
organisation
Vulnerability / Enterprise Security
Swati Khandelwal
Jul 24, 2026
Vulnerability / Enterprise Security
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.
general_metric
24 Khandelwal Jul
Swati Khandelwal
Jul 24, 2026
Vulnerability / Enterprise Security
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.
organisation
The Hacker News
As of July 24, no primary source reviewed by The Hacker News reported exploitation in the wild, but the full proof-of-concept was public.
attribution
Known Exploited
The flaw was absent from
CISA's Known Exploited Vulnerabilities catalog
on July 24.
tactic
T1588.006 - Vulnerabilities
The flaw was absent from
CISA's Known Exploited Vulnerabilities catalog
on July 24.
2026/07/28
Threat actors exploited a vulnerability in Microsoft's Certighost software to gain unauthorized access to domain controllers.
2026/07/28
Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation.
Click on any entity below to view its context and source!
organisation
PoC
Researchers released a proof-of-concept (PoC) exploit for a now-patched flaw in Microsoft's
Active Directory
Certificate Services (AD CS) that can allow a low-privileged domain user to impersonate a domain controller and fully compromise an AD environment.
organisation
Microsoft
Researchers released a proof-of-concept (PoC) exploit for a now-patched flaw in Microsoft's
Active Directory
Certificate Services (AD CS) that can allow a low-privileged domain user to impersonate a domain controller and fully compromise an AD environment.
Microsoft has patched a high-severity vulnerability in Active Directory Certificate Services that allowed a user with basic domain access to obtain a valid certificate identifying them as a
Domain Controller
.
Microsoft patched the Active Directory Certificate Services (AD CS) issue ten days earlier as
CVE-2026-54121
.
organisation
Active Directory
Certificate Services
Researchers released a proof-of-concept (PoC) exploit for a now-patched flaw in Microsoft's
Active Directory
Certificate Services (AD CS) that can allow a low-privileged domain user to impersonate a domain controller and fully compromise an AD environment.
organisation
Active Directory Certificate Services
Microsoft has patched a high-severity vulnerability in Active Directory Certificate Services that allowed a user with basic domain access to obtain a valid certificate identifying them as a
Domain Controller
.
"
Active Directory Certificate Services act as Microsoft's
public key infrastructure
(PKI) implementation that integrates with Active Directory and issues X.509 certificates for purposes such as encryption, signing, secure communications, and authentication, the researchers explained.
organisation
the Active Directory Certificate Services
Microsoft patched the Active Directory Certificate Services (AD CS) issue ten days earlier as
CVE-2026-54121
.
infrastructure
Windows
Related:
Inc Ransomware Exploits SonicWall SMA Zero-Days
How the Certighost Exploit Works
The researchers exploited the flaw in a standard enterprise lab environment featuring an Enterprise CA,
Windows Server Active Directory
, the default machine certificate template, and a low-privilege domain user account.
Microsoft’s advisory lists affected Windows Server releases from Server 2012 through Server 2025, including Server Core installations.
When a certification authority (CA) cannot obtain an end entity's information, the
Windows enrollment protocol
lets a request provide
cdc
, the Active Directory server to contact, and
rmd
, the machine object to resolve.
The public exploit was tested in a Windows Server 2016-or-later forest with an Enterprise CA, the default Machine certificate template, and the default machine-account quota.
The
NVD record
separately lists Windows Server 2012 through Windows Server 2025, including listed Server Core editions, as affected.
It also lists Windows 10 versions 1607 and 1809.
organisation
the Active Directory
When a certification authority (CA) cannot obtain an end entity's information, the
Windows enrollment protocol
lets a request provide
cdc
, the Active Directory server to contact, and
rmd
, the machine object to resolve.
infrastructure
2016 Server
The public exploit was tested in a Windows Server 2016-or-later forest with an Enterprise CA, the default Machine certificate template, and the default machine-account quota.
organisation
NVD
The
NVD record
separately lists Windows Server 2012 through Windows Server 2025, including listed Server Core editions, as affected.
organisation
Certificate Authority Trusted
Certificate Authority Trusted the Wrong Server
Certighost affects a fallback process called a “chase.”
organisation
cdc
The researchers
found
that the CA followed the requester-supplied
cdc
host over Server Message Block (SMB) and Lightweight Directory Access Protocol (LDAP) without first proving it was a real Domain Controller.
"By supplying request attributes such as cdc, an attacker could cause the
Certificate Authority
[CA] to ask an attacker-controlled host for identity data belonging to a Domain Controller.
organisation
Lightweight Directory Access Protocol
The researchers
found
that the CA followed the requester-supplied
cdc
host over Server Message Block (SMB) and Lightweight Directory Access Protocol (LDAP) without first proving it was a real Domain Controller.
The attack chain starts with the script connecting through
LDAP (
Lightweight Directory Access Protocol) with the supplied low-privileged account and discovering the CA, DC, domain SID, and domain GUID.
organisation
Domain Controller
The researchers
found
that the CA followed the requester-supplied
cdc
host over Server Message Block (SMB) and Lightweight Directory Access Protocol (LDAP) without first proving it was a real Domain Controller.
Before Microsoft’s update, the CA could follow the supplied address without first confirming that it belonged to a genuine Domain Controller.
organisation
Aniq Fakhrul
In its July raft of a record 622
Patch Tuesday
updates, Microsoft patched a flaw tracked as
CVE-2026-54121
, which the researchers who discovered and exploited it — Aniq Fakhrul (
@aniqfakhrul
) and Muhammad Ali (
@h0j3n
) — called "Certighost," according to
a post
by the researchers on GitHub.
organisation
Certighost
Tracked as
CVE-2026-54121
and named Certighost, the flaw received a CVSS score of 8.8.
organisation
CVSS
Tracked as
CVE-2026-54121
and named Certighost, the flaw received a CVSS score of 8.8.
Microsoft classed the flaw as improper authorization and assigned it a CVSS score of 8.8.
organisation
Certighost'
'Certighost' Flaw Haunts Microsoft Active Directory Certificates.
organisation
Microsoft Active Directory Certificates
'Certighost' Flaw Haunts Microsoft Active Directory Certificates.
organisation
Microsoft AD Services
The flaw was present due to a defective trust boundary within the certificate-based client authentication aspect of Microsoft AD Services.
organisation
CA
As the researchers described, the vulnerability affects the enterprise certificate authority's (CA) handling of an AD CS enrollment fallback mechanism known as a "chase," which is a second directory lookup performed in some cross-domain controller enrollment scenarios.
The CA would then place the Domain Controller’s SID and DNS name inside a certificate issued to the attacker.
An attacker could run rogue Local Security Authority (LSA) and LDAP services, relay the CA's authentication challenge to the real Domain Controller over
Netlogon
, and return the target Domain Controller's
objectSid
and
dNSHostName
.
organisation
DNS
The CA would then place the Domain Controller’s SID and DNS name inside a certificate issued to the attacker.
"Directory referrals, DNS delegation, and OAuth redirects have all produced the same shape of bug.
It also requires exactly one matching Active Directory computer object whose DNS name matches the target and whose
userAccountControl
includes
SERVER_TRUST_ACCOUNT
(
8192
).
organisation
SID
The CA would then place the Domain Controller’s SID and DNS name inside a certificate issued to the attacker.
The attack chain starts with the script connecting through
LDAP (
Lightweight Directory Access Protocol) with the supplied low-privileged account and discovering the CA, DC, domain SID, and domain GUID.
A later
SID
comparison blocks object substitution.
organisation
LSA
An attacker could run rogue Local Security Authority (LSA) and LDAP services, relay the CA's authentication challenge to the real Domain Controller over
Netlogon
, and return the target Domain Controller's
objectSid
and
dNSHostName
.
"That made it possible for an attacker to run LDAP and LSA services on a host they controlled, direct the CA to that host, and return directory data for a chosen target principal," they wrote.
organisation
Local Security Authority
An attacker could run rogue Local Security Authority (LSA) and LDAP services, relay the CA's authentication challenge to the real Domain Controller over
Netlogon
, and return the target Domain Controller's
objectSid
and
dNSHostName
.
organisation
Netlogon
An attacker could run rogue Local Security Authority (LSA) and LDAP services, relay the CA's authentication challenge to the real Domain Controller over
Netlogon
, and return the target Domain Controller's
objectSid
and
dNSHostName
.
organisation
Fakhrul
Global Users' PII
Because of the flaw, Fakhrul and Ali found that during the issuance of certificates — which bind a subject to a public key — the CA could be tricked into querying an attacker-controlled host for AD identity information by manipulating the cdc (Client DC) and rmd (Remote Domain) request attributes, they explained.
organisation
Certificate Authority
"By supplying request attributes such as cdc, an attacker could cause the
Certificate Authority
[CA] to ask an attacker-controlled host for identity data belonging to a Domain Controller.
organisation
Certighost Abuses a Trust Boundary
Certighost Abuses a Trust Boundary
The vulnerability stemmed from a broken trust boundary within the AD CS certificate enrollment process, which the researchers abused in their PoC attack.
organisation
OAuth
"Directory referrals, DNS delegation, and OAuth redirects have all produced the same shape of bug.
organisation
PKI
"
Active Directory Certificate Services act as Microsoft's
public key infrastructure
(PKI) implementation that integrates with Active Directory and issues X.509 certificates for purposes such as encryption, signing, secure communications, and authentication, the researchers explained.
organisation
Active Directory
"
Active Directory Certificate Services act as Microsoft's
public key infrastructure
(PKI) implementation that integrates with Active Directory and issues X.509 certificates for purposes such as encryption, signing, secure communications, and authentication, the researchers explained.
The findings do not mean every Active Directory deployment could be compromised with the same steps.
organisation
HTTPS
Certificates are often used to sign Web domains to validate HTTPS connections as well as the domains' ownership information.
organisation
the Key Distribution Center
The flaw and PoC involve certificate-based client authentication, in which a client requests a certificate from an enterprise CA and later presents it to the Key Distribution Center (KDC) to obtain Kerberos credentials, they said.
organisation
KDC
The flaw and PoC involve certificate-based client authentication, in which a client requests a certificate from an enterprise CA and later presents it to the Key Distribution Center (KDC) to obtain Kerberos credentials, they said.
organisation
pyasn1
The PoC itself is a self-contained Python script that requires tools such as
Impacket
, pyasn1, asn1crypto, and dnspython, the researchers said.
organisation
Microsoft Fixes Certighost
Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation.
organisation
a Certification Authority
When a Certification Authority cannot resolve identity information during enrollment, it may contact another directory server to complete the lookup.
organisation
Domain Controllers
Since Domain Controllers have directory replication rights, the researchers then used
DCSync
, a post-exploitation cyberattack technique, to retrieve account secrets, including the
krbtgt
credential used by Kerberos.
organisation
Machine
The demonstrated chain depended on specific conditions, including a vulnerable Enterprise CA following the chase path and certificate enrollment being available through the Machine template.
organisation
Chase
Administrators unable to patch immediately can disable the Chase fallback using the policy setting documented by the researchers.
organisation
SMB
The chain also required an Enterprise CA that followed the vulnerable chain path, enrollment through the default Machine template, and network reachability from the CA to the attacker's SMB and LDAP listeners.
organisation
PFX
It then submits the
cdc
and
rmd
attributes and writes a
PFX
file and Kerberos credential cache.
organisation
IP
The validation rejects IP literals, overlong names, and LDAP metacharacters.
organisation
Certificate Services
Administrators who cannot patch immediately can clear the chase flag and restart Certificate Services:
certutil -setreg policy\EditFlags -EDITF_ENABLECHASECLIENTDC
Restart-Service CertSvc -Force
The researchers tested that mitigation only in a controlled lab.
organisation
Restart-Service
Administrators who cannot patch immediately can clear the chase flag and restart Certificate Services:
certutil -setreg policy\EditFlags -EDITF_ENABLECHASECLIENTDC
Restart-Service CertSvc -Force
The researchers tested that mitigation only in a controlled lab.
July 2026
Microsoft fixes a critical vulnerability in Certighost, allowing threat actors to impersonate domain controllers.
2051/07/22
Threat actors exploited a previously unknown vulnerability in Microsoft's Certighost software to gain unauthorized access and impersonate domain controllers.
Click on any entity below to view its context and source!
target_region
United States
Related:
25 Years After Code Red: What the Worm Era Can Teach Us About AI Security
Unfortunately, it's a risk scenario that often is repeated in other standard protocols for such exchanges, he says.
general_metric
25 Years
Related:
25 Years After Code Red: What the Worm Era Can Teach Us About AI Security
Unfortunately, it's a risk scenario that often is repeated in other standard protocols for such exchanges, he says.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Related:
Inc Ransomware Exploits SonicWall SMA Zero-Days
How the Certighost Exploit Works
The researchers exploited the flaw in a standard enterprise lab environment featuring an Enterprise CA,
Windows Server Active Directory
, the default machine certificate template, and a low-privilege domain user account.
Microsoft’s advisory lists affected Windows Server releases from Server 2012 through Server 2025, including Server Core installations.
When a certification authority (CA) cannot obtain an end entity's information, the
Windows enrollment protocol
lets a request provide
cdc
, the Active Directory server to contact, and
rmd
, the machine object to resolve.
The public exploit was tested in a Windows Server 2016-or-later forest with an Enterprise CA, the default Machine certificate template, and the default machine-account quota.
The
NVD record
separately lists Windows Server 2012 through Windows Server 2025, including listed Server Core editions, as affected.
It also lists Windows 10 versions 1607 and 1809.
Metrics
infrastructure
2,016
Server
The public exploit was tested in a Windows Server 2016-or-later forest with an Enterprise CA, the default Machine certificate template, and the default machine-account quota.
Intelligence Sources
The Hacker News
2026-07-24
HackRead
2026-07-27
Dark Reading
2026-07-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-29T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
47x
organisation
Identified Entity
PoC
entity
14x
timeline
Temporal Reference
2051/07/22
date
6x
tactic
MITRE ATT&CK Technique
T1588.005 - Exploits
technique
3x
tactic
Cyber Operation Type
Impersonate
tactic
2x
general metric
Versions
10
versions
Contextual Telemetry
Context Block
10 METRICS
target region
Target Country
United States
country
general metric
Years
25
years
infrastructure
Affected Product
Windows
software
vulnerability
Exploited CVE
CVE-2026-54121
cve
general metric
Patch
622
patch
vulnerability
CVSS Score
9
score
infrastructure
Server
2,016
server
general metric
Khandelwal Jul
24
khandelwal jul
attribution
Attributing Entity
Known Exploited
authority
general metric
Ports
445
ports
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.