Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Certighost Exploit: A Critical Vulnerability Allowing Low-Privileged Active Directory Users to Impersonate Domain Controllers


A newly discovered vulnerability known as Certighost allows low-privileged Active Directory users to impersonate domain controllers, compromising the security posture of organizations reliant on complex IT infrastructures.

  • The Certighost exploit enables low-privileged active directory users to impersonate domain controllers.
  • This vulnerability allows attackers to compromise the security posture of organizations relying on complex IT infrastructures.
  • The exploit was discovered by researchers H0j3n and Aniq Fakhrul in July 2026.
  • Organizations running an Enterprise CA are advised to install Microsoft's July 14 updates on AD CS hosts to prevent exploitation.
  • Patch was assigned a CVSS score of 8.8, underscoring the severity of the issue.
  • The researchers documented a lab-tested way to disable the chase fallback when immediate patching is not possible.



  • The cybersecurity landscape has witnessed numerous threats in recent years, each posing unique challenges to organizations relying on complex IT infrastructures. One such vulnerability that recently came under scrutiny is the Certighost exploit, which enables low-privileged active directory users to impersonate domain controllers. This article delves into the details of this critical vulnerability, its impact on organizations, and the steps being taken to address it.

    In July 2026, researchers H0j3n and Aniq Fakhrul published a working exploit that allows a low-privileged Active Directory user to obtain a certificate for a domain controller and authenticate as that machine. This exploit has been codenamed Certighost, with the researchers highlighting the potential for low-privileged users to manipulate this vulnerability to their advantage. Given that domain controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.

    The discovery of this vulnerability is particularly concerning given that Microsoft patched the Active Directory Certificate Services (AD CS) issue as CVE-2026-54121 ten days earlier. This patch was assigned a CVSS score of 8.8, underscoring the severity of the issue. The researchers found that the chain required an Enterprise CA that followed the vulnerable chain path, enrollment through the default Machine template, and network reachability from the CA to the attacker's SMB and LDAP listeners.

    Organizations running an Enterprise CA are advised to install Microsoft's July 14 updates on AD CS hosts in order to prevent exploitation of this vulnerability. However, it is essential for organizations to take proactive measures given that exploitation requires network access and a domain account, but no administrator rights or user interaction.

    The researchers also documented a lab-tested way to disable the chase fallback when immediate patching is not possible, although it can break legitimate enrollment flows. The bug sits in an AD CS enrollment fallback known as a chase, where a certification authority (CA) cannot obtain an end entity's information and lets a request provide cdc, the Active Directory server, to contact, and rmd, the machine object to resolve.

    An attacker could run rogue Local Security Authority (LSA) and LDAP services, relay the CA's authentication challenge to the real Domain Controller over Netlogon, and return the target Domain Controller's objectSid and DNSHostName. A controlled machine account supplied the valid domain identity needed for the CA to continue. The public exploit automates the chain by creating a computer account or reusing one specified with --computer-name.

    The researchers tested this exploit in a Windows Server 2016-or-later forest with an Enterprise CA, the default Machine certificate template, and the default machine-account quota. The NVD record separately lists Windows Server 2012 through Windows Server 2025, including listed Server Core editions, as affected. It also lists Windows 10 versions 1607 and 1809.

    The impact of this vulnerability cannot be overstated, given its potential to compromise the security posture of organizations relying on Active Directory infrastructures. This exploit allows low-privileged users to impersonate domain controllers, which can lead to unauthorized access to sensitive resources and data.

    Given the severity of this vulnerability, it is crucial for organizations to take immediate action to address it. The researchers have documented a lab-tested way to disable the chase fallback when immediate patching is not possible, although it can break legitimate enrollment flows. Organizations are advised to install Microsoft's July 14 updates on AD CS hosts and stage the mitigation as recommended by the researchers.

    In conclusion, the Certighost exploit represents a critical vulnerability that enables low-privileged active directory users to impersonate domain controllers. Given its severity, organizations must take immediate action to address this issue in order to prevent unauthorized access to sensitive resources and data.

    A newly discovered vulnerability known as Certighost allows low-privileged Active Directory users to impersonate domain controllers, compromising the security posture of organizations reliant on complex IT infrastructures.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Certighost-Exploit-A-Critical-Vulnerability-Allowing-Low-Privileged-Active-Directory-Users-to-Impersonate-Domain-Controllers-ehn.shtml

  • https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html

  • https://cyberwebspider.com/the-hacker-news/certighost-vulnerability-domain-controller/

  • https://origin-unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/


  • Published: Fri Jul 24 10:59:17 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us