
Certighost haunts Microsoft Active Directory Certificate Services
A vulnerability in Microsoft’s Active Directory Certificate Services (AD CS) could allow a low-privilege domain user to impersonate a Domain Controller, security researchers have warned.
Dubbed Certighost, the flaw stems from an enrollment fallback mechanism known as a “chase,” which the Certification Authority (CA) uses during directory-object resolution.
This mechanism could be used to trick the CA into picking up an attacker-controlled identity instead of a legitimate Domain Controller.
“By supplying request attributes such as cdc, an attacker could cause the CA to ask an attacker-controlled host for identity data belonging to a Domain Controller,” researchers @h0j3n, and @aniqfakhrul, sa...