TGViewer
APT APT @apt_notes Β· 16.6K subscribers
Post #1203 5.44K
πŸ”’ Certi-Bhai β€” IIS AppPool β†’ NT AUTHORITY\SYSTEM via AD CS RPC

A webshell under IIS AppPool\DefaultAppPool can enroll against the ADCS RPC endpoint and come back with a certificate for the host machine account. Outbound domain traffic from a virtual AppPool identity is authenticated as HOST$, so the default Machine template treats the CSR as a legitimate computer enrollment.
The issued cert produces a PKINIT TGT for that machine account. S4U2Self turns it into an Administrator CIFS ticket on the same box, which is local SYSTEM-equivalent access and a path to hash dump. Potato-family impersonation is not part of the chain.

πŸ”— Research:
https://www.mannulinux.org/2026/08/Privilege-escalation-from-IIS-AppPool-to-NT-AuthoritySYSTEM-via-AD-CS-RPC-endpoint.html

πŸ”— Source:
https://github.com/incredibleindishell/Certi-Bhai

#ad #adcs #iis #privesc #pkinit #s4u2self #windows
  • πŸ”₯ 12
  • ❀ 6
  • πŸ‘ 2
  • 😁 1
More from @apt_notes
  1. Aug 17, 2026πŸ”’ Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) Unauthenticated heap overflow in SAML sig…
  2. Aug 11, 2026Post #1201
  3. Aug 7, 2026ResetNightmare ResetNightmare (CVE-2026-27912) is a validation flaw in the Kerberos Change…
  4. Jul 24, 2026πŸ”’ Certighost (CVE-2026-54121) β€” AD CS Domain Controller Impersonation Low-privileged doma…
  5. Jul 9, 2026πŸ’‰ PΒ³ β€” Shellcode Loader: Process Parameter Poisoning This loader implements a code inject…
  6. Jul 8, 2026GhostLock β€” CVE-2026-43499 This is a Linux kernel vulnerability found by VEGA that exists…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’