TGViewer
APT APT @apt_notes · 16.6K subscribers
Post #1199 27.8K
🔒 Certighost (CVE-2026-54121) — AD CS Domain Controller Impersonation

Low-privileged domain user can impersonate a Domain Controller via an AD CS enrollment chase fallback. By supplying cdc (Client DC) and rmd (Remote Domain) request attributes, an attacker forces the Enterprise CA to query an attacker-controlled host over SMB and LDAP.

The CA then blindly trusts the returned directory objects (objectSid + dNSHostName of a real DC) and issues a certificate containing strong identity mapping for the Domain Controller. This allows successful PKINIT authentication as the DC.

🔗 Research:
https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26

🔗 Source:
https://github.com/aniqfakhrul/CVE-2026-54121

#ad #adcs #pkinit #machineaccountquota
  • 🔥 26
  • ❤ 7
  • 👍 2
  • 😱 2
  • 👎 1
More from @apt_notes
  1. Sep 1, 2026🔒 Certi-Bhai — IIS AppPool → NT AUTHORITY\SYSTEM via AD CS RPC A webshell under IIS AppPo…
  2. Aug 17, 2026🔒 Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) Unauthenticated heap overflow in SAML sig…
  3. Aug 11, 2026Post #1201
  4. Aug 7, 2026ResetNightmare ResetNightmare (CVE-2026-27912) is a validation flaw in the Kerberos Change…
  5. Jul 9, 2026💉 P³ — Shellcode Loader: Process Parameter Poisoning This loader implements a code inject…
  6. Jul 8, 2026GhostLock — CVE-2026-43499 This is a Linux kernel vulnerability found by VEGA that exists…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →